• DocumentCode
    2454355
  • Title

    Detecting privacy infractions in applications: A framework and methodology

  • Author

    Smit, Michael ; Lyons, Kelly ; McAllister, Michael ; Slonim, Jacob

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Alberta, Edmonton, AB, Canada
  • fYear
    2009
  • fDate
    12-15 Oct. 2009
  • Firstpage
    694
  • Lastpage
    701
  • Abstract
    We describe a framework and methodology for managing the privacy policy of an enterprise, including creation (based on factors like legislation and consumer preferences), validation and verification, deployment and enforcement, and compliance testing for business processes and software. To evaluate this approach, one module of our framework (compliance testing) is implemented for an existing prominent electronic commerce software application. Our unique approach monitors the personal information sent and received by the software application and converts it to a standardized representation. At defined points in the electronic commerce workflow, the transmissions are compared to a set of privacy rules (extracted from a privacy policy) to ascertain compliance. Non-compliant transmissions of personal information are labeled `potential privacy infractions´ and are reported. Though presently implemented for software testing, ultimately the methodology is intended to halt or alter a workflow to avoid privacy infractions.
  • Keywords
    conformance testing; data privacy; electronic commerce; legislation; program testing; program verification; workflow management software; business process; consumer preference factor; electronic commerce workflow software application; enterprise privacy policy management; legislation factor; noncompliant personal information transmission; privacy infraction detection; software compliance testing; software validation; software verification; Application software; Business; Data mining; Data privacy; Electronic commerce; Pervasive computing; Protection; Security; Software systems; Software testing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Mobile Adhoc and Sensor Systems, 2009. MASS '09. IEEE 6th International Conference on
  • Conference_Location
    Macau
  • Print_ISBN
    978-1-4244-5113-5
  • Type

    conf

  • DOI
    10.1109/MOBHOC.2009.5336935
  • Filename
    5336935