作者
Mina Deng, Kim Wuyts, Riccardo Scandariato, Bart Preneel, Wouter Joosen
发表日期
2011/3
期刊
Requirements Engineering
卷号
16
期号
1
页码范围
3-32
出版商
Springer-Verlag
简介
Ready or not, the digitalization of information has come, and privacy is standing out there, possibly at stake. Although digital privacy is an identified priority in our society, few systematic, effective methodologies exist that deal with privacy threats thoroughly. This paper presents a comprehensive framework to model privacy threats in software-based systems. First, this work provides a systematic methodology to model privacy-specific threats. Analogous to STRIDE, an information flow–oriented model of the system is leveraged to guide the analysis and to provide broad coverage. The methodology instructs the analyst on what issues should be investigated, and where in the model those issues could emerge. This is achieved by (i) defining a list of privacy threat types and (ii) providing the mappings between threat types and the elements in the system model. Second, this work provides an extensive catalog of …
引用总数
201020112012201320142015201620172018201920202021202220232024238182231443663577969777663
学术搜索中的文章