Models of Applied Privacy (MAP): A Persona Based Approach to Threat Modeling
Title of the Paper
Models of Applied Privacy (MAP): A Persona Based Approach to Threat Modeling
Paper Information
- Topic Area: Privacy threat modeling, development of privacy personas
- Keywords: Privacy, privacy threat modeling, framework, personalization, privacy protection, developer tools, security, risk assessment, privacy design, artificial intelligence
- Conference: CHI ’23 (The 2023 CHI Conference on Human Factors in Computing Systems)
- DOI: https://doi.org/10.1145/3544548.3581484
Research Background and Issues
-
Problems and Challenges:
- Current privacy threat modeling frameworks (e.g., LINDDUN) have the following shortcomings:
- Overly narrow perspectives, focusing either on attackers, vulnerabilities, or assets, failing to provide a comprehensive view of privacy threats.
- Difficulty in distinguishing impacts on individuals versus organizations.
- Most frameworks focus solely on malicious threats, neglecting privacy risks caused unintentionally by "well-meaning" actors.
- Broad and generalized frameworks make it challenging for developers to apply them quickly during development cycles.
- Developers need significant expertise in privacy, increasing the difficulty of using these tools.
- Existing privacy threat models are hard to scale and operationalize, limiting their application to small-scale systems.
- Current privacy threat modeling frameworks (e.g., LINDDUN) have the following shortcomings:
-
Research Importance:
- Privacy issues are increasingly critical to user trust, and the concept of Privacy by Design needs to be integrated early into development processes to mitigate privacy risks in final products.
- Threat modeling is a key step in identifying potential privacy vulnerabilities in systems, necessitating the design of new methods that are easier to implement and require less specialized knowledge.
-
Research Motivation and Related Work:
- Inspired by security card games (e.g., STRIDE and PASTA) and the successful use of user personas in design.
- Exploring the redesign of user personas into privacy threat actors to create a lightweight, intuitive, and scalable privacy threat modeling tool.
Solution
-
Proposed Method:
- The study introduces a new framework: MAP (Models of Applied Privacy).
- MAP uses a persona-based approach to break privacy threat modeling into:
- Threat Actors, encompassing internal and external actors, both well-meaning and malicious.
- Threat Mechanisms, referencing existing privacy frameworks like LINDDUN and NIST PRAM.
- Threat Impacts, covering privacy harms to individuals and organizations.
-
Innovations:
- Redesigning "user personas" into "threat personas," providing additional contextual information for identifying privacy threats.
- Enabling developers to quickly select threat personas, making the tool accessible to non-privacy experts.
- Restructuring existing frameworks to enhance flexibility, scalability, and usability.
- Addressing not only malicious threats but also privacy risks caused by well-meaning actions.
-
Implementation Steps:
- Understanding the framework: including the three core elements of threat actors, mechanisms, and impacts.
- Constructing personas based on the framework, allowing developers to automatically generate combined personas by selecting different categories.
- Using personas to model privacy scenarios in applications, execute tests, extract key privacy risks, and develop mitigation measures.
-
Key Technologies:
- Inspired by the "fishbone diagram" causal analysis model.
- Combining known privacy threat classifications (e.g., LINDDUN, NIST PRAM) to build a transparent and granular threat classification library.
- Developing a comprehensive component selection menu to support user interaction.
Research Results
-
Specific Outcomes:
- Developed the MAP framework, enabling privacy risk assessment from the perspectives of threat actors, mechanisms, and impacts.
- Provided multiple case studies to demonstrate how to create detailed threat personas.
- Validated the framework's generalizability using the VERIS incident database, covering approximately 96% of privacy threat classifications.
-
Advantages Compared to Existing Solutions:
- Compared to traditional frameworks, the MAP framework is easier to use, requiring minimal specialized privacy knowledge from developers.
- Combining the user persona method with privacy modeling enhances the depth and breadth of understanding threat actors.
- Highly scalable, applicable across industries and various application scenarios.
-
Experimental and Evaluation Results:
- In tests using the VCDB database, the MAP framework successfully classified 183 out of 207 historical privacy incidents (88.4% coverage).
- Identified common threat patterns and key impact categories, such as "neutral internal actors" accounting for the majority (152 cases).
-
Limitations and Future Directions:
- Current validation of the framework focuses on specific databases (e.g., VCDB); future work should incorporate more diverse industry data sources for validation.
- Personalized threat personas generated by MAP may lack detailed extensions for specific application scenarios, requiring optimization of its scaling dictionary mechanism.
- Future research should include user studies (e.g., testing interactions between developers and privacy threat analysts) to refine the usage process.
Conclusion
The MAP framework introduces a novel perspective to privacy threat modeling, integrating design concepts from user personas with the needs of privacy and security domains. By optimizing the design of threat persona tools, the MAP framework provides a simple-to-operate mechanism for identifying privacy threats to a broader developer audience, while enhancing the execution and applicability of system privacy protection.
Research Questions / Practical Problems
Question signals indexed for this paper.
Research Questions
3- How can user role models be redesigned for privacy threat modeling to more intuitively discover threats?Category: Developer and Organizational Privacy and Security PracticesSimilar questionsarrow_forward
- How do the three core elements of the MAP framework (threat actors, mechanisms, and impacts) work together to identify privacy threats?Category: Developer and Organizational Privacy and Security PracticesSimilar questionsarrow_forward
- Can the new privacy threat modeling tool lower the barrier for developers and optimize its practical application scope?Category: Developer and Organizational Privacy and Security PracticesSimilar questionsarrow_forward
Practical Problems
1- Developers struggle to quickly identify privacy threats and lack easy-to-use modeling tools.Category: Developer and Organizational Privacy and Security PracticesSimilar questionsarrow_forward
- 63%
Sensor Illumination: Exploring Design Qualities and Ethical Implications of Smart Cameras and Image/Video Analytics
CHI '20· Privacy by Design & User Control +2
- 63%
UI Dark Patterns and Where to Find Them: A Study on Mobile Applications and User Perception
CHI '20· Algorithmic Transparency & Auditability +2
- 63%
"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
CHI '22· Privacy by Design & User Control +2
- 63%
Understanding Challenges for Developers to Create Accurate Privacy Nutrition Labels
CHI '22· Privacy by Design & User Control +1
- 63%
Permission vs. App Limiters: Profiling Smartphone Users to Understand Differing Strategies for Mobile Privacy Management
CHI '22· Privacy by Design & User Control +2
- 63%
Encoding Privacy: Sociotechnical Dynamics of Data Protection Compliance Work
CHI '24· AI Ethics, Fairness & Accountability +2
- 63%
Who am I Talking to? A Large-Scale Measurement of Surface Attribution Across Real-World Security and Privacy Interfaces
CHI '26· Privacy by Design & User Control +2
- 63%
Helping Johnny Make Sense of Privacy Policies with LLMs
CHI '26· Privacy by Design & User Control +2
- 63%
Too Many Zombies: Exploring Challenges and Motivations for (Not) Deleting Unused Online Accounts
CHI '26· Privacy by Design & User Control +2
- 63%
IoTBeholder: A Privacy Snooping Attack on User Habitual Behaviors from Smart Home Wi-Fi Traffic
UbiComp '23· Privacy by Design & User Control +2
Based on Jaccard similarity of research subtopics & professions (≥60%)