Models of Applied Privacy (MAP): A Persona Based Approach to Threat Modeling

Algorithmic Transparency & AuditabilityPrivacy by Design & User ControlPrivacy Perception & Decision-MakingSoftware Engineers & DevelopersUI/UX DesignersCybersecurity EngineersPrivacy Policy Makers

Title of the Paper

Models of Applied Privacy (MAP): A Persona Based Approach to Threat Modeling

Paper Information

  • Topic Area: Privacy threat modeling, development of privacy personas
  • Keywords: Privacy, privacy threat modeling, framework, personalization, privacy protection, developer tools, security, risk assessment, privacy design, artificial intelligence
  • Conference: CHI ’23 (The 2023 CHI Conference on Human Factors in Computing Systems)
  • DOI: https://doi.org/10.1145/3544548.3581484

Research Background and Issues

  • Problems and Challenges:

    • Current privacy threat modeling frameworks (e.g., LINDDUN) have the following shortcomings:
      • Overly narrow perspectives, focusing either on attackers, vulnerabilities, or assets, failing to provide a comprehensive view of privacy threats.
      • Difficulty in distinguishing impacts on individuals versus organizations.
      • Most frameworks focus solely on malicious threats, neglecting privacy risks caused unintentionally by "well-meaning" actors.
      • Broad and generalized frameworks make it challenging for developers to apply them quickly during development cycles.
      • Developers need significant expertise in privacy, increasing the difficulty of using these tools.
    • Existing privacy threat models are hard to scale and operationalize, limiting their application to small-scale systems.
  • Research Importance:

    • Privacy issues are increasingly critical to user trust, and the concept of Privacy by Design needs to be integrated early into development processes to mitigate privacy risks in final products.
    • Threat modeling is a key step in identifying potential privacy vulnerabilities in systems, necessitating the design of new methods that are easier to implement and require less specialized knowledge.
  • Research Motivation and Related Work:

    • Inspired by security card games (e.g., STRIDE and PASTA) and the successful use of user personas in design.
    • Exploring the redesign of user personas into privacy threat actors to create a lightweight, intuitive, and scalable privacy threat modeling tool.

Solution

  • Proposed Method:

    • The study introduces a new framework: MAP (Models of Applied Privacy).
    • MAP uses a persona-based approach to break privacy threat modeling into:
      1. Threat Actors, encompassing internal and external actors, both well-meaning and malicious.
      2. Threat Mechanisms, referencing existing privacy frameworks like LINDDUN and NIST PRAM.
      3. Threat Impacts, covering privacy harms to individuals and organizations.
  • Innovations:

    1. Redesigning "user personas" into "threat personas," providing additional contextual information for identifying privacy threats.
    2. Enabling developers to quickly select threat personas, making the tool accessible to non-privacy experts.
    3. Restructuring existing frameworks to enhance flexibility, scalability, and usability.
    4. Addressing not only malicious threats but also privacy risks caused by well-meaning actions.
  • Implementation Steps:

    1. Understanding the framework: including the three core elements of threat actors, mechanisms, and impacts.
    2. Constructing personas based on the framework, allowing developers to automatically generate combined personas by selecting different categories.
    3. Using personas to model privacy scenarios in applications, execute tests, extract key privacy risks, and develop mitigation measures.
  • Key Technologies:

    • Inspired by the "fishbone diagram" causal analysis model.
    • Combining known privacy threat classifications (e.g., LINDDUN, NIST PRAM) to build a transparent and granular threat classification library.
    • Developing a comprehensive component selection menu to support user interaction.

Research Results

  • Specific Outcomes:

    • Developed the MAP framework, enabling privacy risk assessment from the perspectives of threat actors, mechanisms, and impacts.
    • Provided multiple case studies to demonstrate how to create detailed threat personas.
    • Validated the framework's generalizability using the VERIS incident database, covering approximately 96% of privacy threat classifications.
  • Advantages Compared to Existing Solutions:

    • Compared to traditional frameworks, the MAP framework is easier to use, requiring minimal specialized privacy knowledge from developers.
    • Combining the user persona method with privacy modeling enhances the depth and breadth of understanding threat actors.
    • Highly scalable, applicable across industries and various application scenarios.
  • Experimental and Evaluation Results:

    • In tests using the VCDB database, the MAP framework successfully classified 183 out of 207 historical privacy incidents (88.4% coverage).
    • Identified common threat patterns and key impact categories, such as "neutral internal actors" accounting for the majority (152 cases).
  • Limitations and Future Directions:

    • Current validation of the framework focuses on specific databases (e.g., VCDB); future work should incorporate more diverse industry data sources for validation.
    • Personalized threat personas generated by MAP may lack detailed extensions for specific application scenarios, requiring optimization of its scaling dictionary mechanism.
    • Future research should include user studies (e.g., testing interactions between developers and privacy threat analysts) to refine the usage process.

Conclusion

The MAP framework introduces a novel perspective to privacy threat modeling, integrating design concepts from user personas with the needs of privacy and security domains. By optimizing the design of threat persona tools, the MAP framework provides a simple-to-operate mechanism for identifying privacy threats to a broader developer audience, while enhancing the execution and applicability of system privacy protection.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/96103/2023

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://doi.org/10.1145/3544548.3581484
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2023
emoji_events
Award
No award tagged
group
Authors
3 authors
sell
Subtopics
Algorithmic Transparency & Auditability, Privacy by Design & User Control, Privacy Perception & Decision-Making
work
Professions
Software Engineers & Developers, UI/UX Designers, Cybersecurity Engineers, Privacy Policy Makers
article
Content Status
Full text indexed
hub
Related Papers
10 related papers