Privacy Property Graph: Towards Automated Privacy Threat Modeling via Static Graph-based Analysis

Privacy threat modeling should be done frequently throughout development and production to be able to quickly mitigate threats. Yet, it can also be a very time-consuming activity. In this paper, we use an enhanced code property graph to partly automate the privacy threat modeling process: It automat...

Full description

Saved in:
Bibliographic Details
Published inProceedings on Privacy Enhancing Technologies Vol. 2023; no. 2; pp. 171 - 187
Main Authors Kunz, Immanuel, Weiss, Konrad, Schneider, Angelika, Banse, Christian
Format Journal Article
LanguageEnglish
Published 01.04.2023
Online AccessGet full text

Cover

Loading…
More Information
Summary:Privacy threat modeling should be done frequently throughout development and production to be able to quickly mitigate threats. Yet, it can also be a very time-consuming activity. In this paper, we use an enhanced code property graph to partly automate the privacy threat modeling process: It automatically generates a data flow diagram from source code which exhibits privacy properties of data flows, and which can be analyzed semi-automatically via queries. We provide a list of such reusable queries that can be used to detect various privacy threats. To enable this analysis, we integrate a taint-tracking mechanism into the graph using privacy-specific labels. Since no benchmark for such an approach exists, we also present a test suite for privacy threat implementations which comprises implementations for 22 privacy threats in multiple programming languages. We expect that our approach significantly reduces time consumption of threat modeling and show that it also has potential beyond the threat categories defined by LINDDUN, e.g. to detect privacy anti-patterns and verify compliance to privacy policies.
ISSN:2299-0984
2299-0984
DOI:10.56553/popets-2023-0046