CRApr 3, 2016

Design and implementation of the advanced cloud privacy threat modeling

arXiv:1604.00666v14 citations
Originality Synthesis-oriented
AI Analysis

This work addresses privacy preservation for sensitive data in cloud environments, but it is incremental as it builds upon an existing methodology.

The paper tackles privacy threats in cloud computing by extending the Cloud Privacy Threat Modeling methodology, applying Method Engineering to specify its characteristics and steps, and demonstrating its usability through a case study as a proof of concept.

Privacy-preservation for sensitive data has become a challenging issue in cloud computing. Threat modeling as a part of requirements engineering in secure software development provides a structured approach for identifying attacks and proposing countermeasures against the exploitation of vulnerabilities in a system . This paper describes an extension of Cloud Privacy Threat Modeling (CPTM) methodology for privacy threat modeling in relation to processing sensitive data in cloud computing environments. It describes the modeling methodology that involved applying Method Engineering to specify characteristics of a cloud privacy threat modeling methodology, different steps in the proposed methodology and corresponding products. In addition, a case study has been implemented as a proof of concept to demonstrate the usability of the proposed methodology. We believe that the extended methodology facilitates the application of a privacy-preserving cloud software development approach from requirements engineering to design.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes