DocumentCode
3685962
Title
Detecting repurposing and over-collection in multi-party privacy requirements specifications
Author
Travis D. Breaux;Daniel Smullen;Hanan Hibshi
Author_Institution
Inst. of Software Res., Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear
2015
Firstpage
166
Lastpage
175
Abstract
Mobile and web applications increasingly leverage service-oriented architectures in which developers integrate third-party services into end user applications. This includes identity management, mapping and navigation, cloud storage, and advertising services, among others. While service reuse reduces development time, it introduces new privacy and security risks due to data repurposing and over-collection as data is shared among multiple parties who lack transparency into third-party data practices. To address this challenge, we propose new techniques based on Description Logic (DL) for modeling multiparty data flow requirements and verifying the purpose specification and collection and use limitation principles, which are prominent privacy properties found in international standards and guidelines. We evaluate our techniques in an empirical case study that examines the data practices of the Waze mobile application and three of their service providers: Facebook Login, Amazon Web Services (a cloud storage provider), and Flurry.com (a popular mobile analytics and advertising platform). The study results include detected conflicts and violations of the principles as well as two patterns for balancing privacy and data use flexibility in requirements specifications. Analysis of automation reasoning over the DL models show that reasoning over complex compositions of multi-party systems is feasible within exponential asymptotic timeframes proportional to the policy size, the number of expressed data, and orthogonal to the number of conflicts found.
Keywords
"Data privacy","Privacy","Terminology","Facebook","Limiting","Advertising"
Publisher
ieee
Conference_Titel
Requirements Engineering Conference (RE), 2015 IEEE 23rd International
Type
conf
DOI
10.1109/RE.2015.7320419
Filename
7320419
Link To Document