• DocumentCode
    3572025
  • Title

    Caprice: a tool for engineering adaptive privacy

  • Author

    Omoronyia, Inah ; Pasquale, Liliana ; Salehie, Mazeiar ; Cavallaro, Luca ; Doherty, Gavin ; Nuseibeh, Bashar

  • Author_Institution
    Lero-The Irish Software Eng. Res. Centre, Univ. of Limerick, Limerick, Ireland
  • fYear
    2012
  • Firstpage
    354
  • Lastpage
    357
  • Abstract
    In a dynamic environment where context changes frequently, users´ privacy requirements can also change. To satisfy such changing requirements, there is a need for continuous analysis to discover new threats and possible mitigation actions. A frequently changing context can also blur the boundary between public and personal space, making it difficult for users to discover and mitigate emerging privacy threats. This challenge necessitates some degree of self-adaptive privacy management in software applications. This paper presents Caprice - a tool for enabling software engineers to design systems that discover and mitigate context-sensitive privacy threats. The tool uses privacy policies, and associated domain and software behavioural models, to reason over the contexts that threaten privacy. Based on the severity of a discovered threat, adaptation actions are then suggested to the designer. We present the Caprice architecture and demonstrate, through an example, that the tool can enable designers to focus on specific privacy threats that arise from changing context and the plausible category of adaptation action, such as ignoring, preventing, reacting, and terminating interactions that threaten privacy.
  • Keywords
    data privacy; software engineering; software tools; Caprice; context-sensitive privacy threat discovery; context-sensitive privacy threat mitigation; engineering adaptive privacy; mitigation actions; privacy policies; self-adaptive privacy management; software behavioural models; user privacy requirements; Privacy; adaptive software; changing context; selective disclosure;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Automated Software Engineering (ASE), 2012 Proceedings of the 27th IEEE/ACM International Conference on
  • Print_ISBN
    978-1-4503-1204-2
  • Type

    conf

  • DOI
    10.1145/2351676.2351745
  • Filename
    6494954