IEEE Technology and Society Magazine - Winter 2014 - 79
extension of the CORAS methodology for risk assessment [19].
Threat scenarios depict with a
level of probability how threats can
cause incidents by means of exploiting existing vulnerabilities. Incidents have negative consequences
on assets owned by stakeholders
with a level of severity, for example, the result of a leak of presence
information may trigger a privacy
violation. The result risk calculation of a threat scenario is done
considering the probability versus
the severity of the negative consequences caused by the resulting
incidents. One threat scenario may
enable other contained threat scenarios to happen, given that additional vulnerabilities are present.
Citizen/users can maintain a history
of incidents and exchange information with respect to occurrence of
threat scenarios enabling empirical
statistical analysis of risks.
Threats, assets, and vulnerabilities are associated with the system
elements defined in the collection of
SecKit metamodels and are not specified in isolation. This association
provides traceability of risks, supports structured analysis, and allows
more concrete countermeasures
to be adopted. Each citizen/user
may decide to adopt the indicated
countermeasures if the risk level is
above a certain personal threshold.
In SecKit we associate the countermeasures with a set of rule templates
that can be deployed and enforced to
detect and react or prevent the threat
scenario from happening.
Fig. 4 shows an example risk
model where the threat scenarios
are analyzed and the countermeasures are identified. In this example a threat scenario is specified
for an IoT device in a smart home
that allows external entities deliberate access to information, and
as a consequence, these entities
can infer if the home owner is at
home or not. This threat scenario
enables a second threat scenario
where thieves rob the smart home
when the owner is not at home. One
possible countermeasure to mitigate the enabling threat scenario
is to instantiate a security policy
rule template that control external
access to the IoT device. This is
a policy template specified in the
ECA format that can be deployed
and enforced. More abstract countermeasures can also be specified,
for example, to deploy an effective
alarm system that prevents thieves
from robbing the citizens' home.
Future Developments
The adoption of SecKit as a common
abstract platform to enable trust and
privacy has many advantages from
a citizen's perspective. It allows the
collaboration between citizens with a
precise definition of trust beliefs and
trust management approaches. Observations about trust can be exchanged
together with the management policy
rule templates adopted, explicitly
IEEE TECHNOLOGY AND SOCIETY MAGAZINE
making the semantics and interpretation of these trust values easier. It also
enables a community-driven privacy
support that can be updated on a regular basis with support not only from
the citizens' peers via social networks
but also from privacy protection organizations that actively work on risk
assessment and specification of possible countermeasures.
Technical solutions embedded by
design in the systems and the creation
of places for individuals to control and
shape their own choices in design, can
represent a step forward in achieving
a higher level of trust. Trust, however,
does not entirely depend on the effective control of the system. Indeed,
trust can be maintained and nurtured
even when the complexities of linkages is so high that the system can
only notify and raise awareness that
a critical threshold of uncertainty has
been reached.
Fig.3. Trust management policy rule templates.
Fig.4. Risk model.
|
WINTER 2014
|
79
Table of Contents for the Digital Edition of IEEE Technology and Society Magazine - Winter 2014
IEEE Technology and Society Magazine - Winter 2014 - Cover1
IEEE Technology and Society Magazine - Winter 2014 - Cover2
IEEE Technology and Society Magazine - Winter 2014 - 1
IEEE Technology and Society Magazine - Winter 2014 - 2
IEEE Technology and Society Magazine - Winter 2014 - 3
IEEE Technology and Society Magazine - Winter 2014 - 4
IEEE Technology and Society Magazine - Winter 2014 - 5
IEEE Technology and Society Magazine - Winter 2014 - 6
IEEE Technology and Society Magazine - Winter 2014 - 7
IEEE Technology and Society Magazine - Winter 2014 - 8
IEEE Technology and Society Magazine - Winter 2014 - 9
IEEE Technology and Society Magazine - Winter 2014 - 10
IEEE Technology and Society Magazine - Winter 2014 - 11
IEEE Technology and Society Magazine - Winter 2014 - 12
IEEE Technology and Society Magazine - Winter 2014 - 13
IEEE Technology and Society Magazine - Winter 2014 - 14
IEEE Technology and Society Magazine - Winter 2014 - 15
IEEE Technology and Society Magazine - Winter 2014 - 16
IEEE Technology and Society Magazine - Winter 2014 - 17
IEEE Technology and Society Magazine - Winter 2014 - 18
IEEE Technology and Society Magazine - Winter 2014 - 19
IEEE Technology and Society Magazine - Winter 2014 - 20
IEEE Technology and Society Magazine - Winter 2014 - 21
IEEE Technology and Society Magazine - Winter 2014 - 22
IEEE Technology and Society Magazine - Winter 2014 - 23
IEEE Technology and Society Magazine - Winter 2014 - 24
IEEE Technology and Society Magazine - Winter 2014 - 25
IEEE Technology and Society Magazine - Winter 2014 - 26
IEEE Technology and Society Magazine - Winter 2014 - 27
IEEE Technology and Society Magazine - Winter 2014 - 28
IEEE Technology and Society Magazine - Winter 2014 - 29
IEEE Technology and Society Magazine - Winter 2014 - 30
IEEE Technology and Society Magazine - Winter 2014 - 31
IEEE Technology and Society Magazine - Winter 2014 - 32
IEEE Technology and Society Magazine - Winter 2014 - 33
IEEE Technology and Society Magazine - Winter 2014 - 34
IEEE Technology and Society Magazine - Winter 2014 - 35
IEEE Technology and Society Magazine - Winter 2014 - 36
IEEE Technology and Society Magazine - Winter 2014 - 37
IEEE Technology and Society Magazine - Winter 2014 - 38
IEEE Technology and Society Magazine - Winter 2014 - 39
IEEE Technology and Society Magazine - Winter 2014 - 40
IEEE Technology and Society Magazine - Winter 2014 - 41
IEEE Technology and Society Magazine - Winter 2014 - 42
IEEE Technology and Society Magazine - Winter 2014 - 43
IEEE Technology and Society Magazine - Winter 2014 - 44
IEEE Technology and Society Magazine - Winter 2014 - 45
IEEE Technology and Society Magazine - Winter 2014 - 46
IEEE Technology and Society Magazine - Winter 2014 - 47
IEEE Technology and Society Magazine - Winter 2014 - 48
IEEE Technology and Society Magazine - Winter 2014 - 49
IEEE Technology and Society Magazine - Winter 2014 - 50
IEEE Technology and Society Magazine - Winter 2014 - 51
IEEE Technology and Society Magazine - Winter 2014 - 52
IEEE Technology and Society Magazine - Winter 2014 - 53
IEEE Technology and Society Magazine - Winter 2014 - 54
IEEE Technology and Society Magazine - Winter 2014 - 55
IEEE Technology and Society Magazine - Winter 2014 - 56
IEEE Technology and Society Magazine - Winter 2014 - 57
IEEE Technology and Society Magazine - Winter 2014 - 58
IEEE Technology and Society Magazine - Winter 2014 - 59
IEEE Technology and Society Magazine - Winter 2014 - 60
IEEE Technology and Society Magazine - Winter 2014 - 61
IEEE Technology and Society Magazine - Winter 2014 - 62
IEEE Technology and Society Magazine - Winter 2014 - 63
IEEE Technology and Society Magazine - Winter 2014 - 64
IEEE Technology and Society Magazine - Winter 2014 - 65
IEEE Technology and Society Magazine - Winter 2014 - 66
IEEE Technology and Society Magazine - Winter 2014 - 67
IEEE Technology and Society Magazine - Winter 2014 - 68
IEEE Technology and Society Magazine - Winter 2014 - 69
IEEE Technology and Society Magazine - Winter 2014 - 70
IEEE Technology and Society Magazine - Winter 2014 - 71
IEEE Technology and Society Magazine - Winter 2014 - 72
IEEE Technology and Society Magazine - Winter 2014 - 73
IEEE Technology and Society Magazine - Winter 2014 - 74
IEEE Technology and Society Magazine - Winter 2014 - 75
IEEE Technology and Society Magazine - Winter 2014 - 76
IEEE Technology and Society Magazine - Winter 2014 - 77
IEEE Technology and Society Magazine - Winter 2014 - 78
IEEE Technology and Society Magazine - Winter 2014 - 79
IEEE Technology and Society Magazine - Winter 2014 - 80
IEEE Technology and Society Magazine - Winter 2014 - Cover3
IEEE Technology and Society Magazine - Winter 2014 - Cover4
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2023
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2022
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2021
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2020
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2019
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_december2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_september2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_june2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_march2018
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2017
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2016
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2015
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2014
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_winter2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_fall2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_summer2013
https://www.nxtbook.com/nxtbooks/ieee/technologysociety_spring2013
https://www.nxtbookmedia.com