Target Privacy Threat Modeling for COVID-19 Exposure Notification Systems

09/25/2020
by   Ananya Gangavarapu, et al.
0

The adoption of digital contact tracing (DCT) technology during the COVID-19pandemic has shown multiple benefits, including helping to slow the spread of infectious disease and to improve the dissemination of accurate information. However, to support both ethical technology deployment and user adoption, privacy must be at the forefront. With the loss of privacy being a critical threat, thorough threat modeling will help us to strategize and protect privacy as digital contact tracing technologies advance. Various threat modeling frameworks exist today, such as LINDDUN, STRIDE, PASTA, and NIST, which focus on software system privacy, system security, application security, and data-centric risk, respectively. When applied to the exposure notification system (ENS) context, these models provide a thorough view of the software side but fall short in addressing the integrated nature of hardware, humans, regulations, and software involved in such systems. Our approach addresses ENSsas a whole and provides a model that addresses the privacy complexities of a multi-faceted solution. We define privacy principles, privacy threats, attacker capabilities, and a comprehensive threat model. Finally, we outline threat mitigation strategies that address the various threats defined in our model

READ FULL TEXT
research
07/14/2020

Public Goods From Private Data – An Efficacy and Justification Paradox for Digital Contact Tracing

Debate about the adoption of digital contact tracing (DCT) apps to contr...
research
02/24/2019

EUI-64 Considered Harmful

This position paper considers the privacy and security implications of E...
research
11/17/2021

Privacy Guarantees of BLE Contact Tracing: A Case Study on COVIDWISE

Google and Apple jointly introduced a digital contact tracing technology...
research
11/15/2019

Integrating Threat Modeling and Automated Test Case Generation into Industrialized Software Security Testing

Industrial Internet of Things (IIoT) application provide a whole new set...
research
09/01/2018

Privacy, ethics, and data access: A case study of the Fragile Families Challenge

Stewards of social science data face a fundamental tension. On one hand,...
research
07/20/2022

Fair Context-Aware Privacy Threat Modelling

Given the progressive nature of the world today, fairness is a very impo...
research
08/22/2023

Up-to-date Threat Modelling for Soft Privacy on Smart Cars

Physical persons playing the role of car drivers consume data that is so...

Please sign up or login with your details

Forgot password? Click here to reset