Design and implementation of the advanced cloud privacy threat modeling
Ali Gholami, Anna-Sara Lind, Jane Reichel, Jan-Eric Litton, Ake, Edlund, Erwin Laure

TL;DR
This paper extends a cloud privacy threat modeling methodology to better identify and mitigate risks associated with processing sensitive data in cloud environments, supporting privacy-preserving software development.
Contribution
It introduces an extended CPTM methodology using Method Engineering, with detailed steps and a case study demonstrating its practical application.
Findings
Enhanced privacy threat modeling methodology for cloud computing.
Successful case study validation of the proposed approach.
Facilitates privacy-preserving cloud software development.
Abstract
Privacy-preservation for sensitive data has become a challenging issue in cloud computing. Threat modeling as a part of requirements engineering in secure software development provides a structured approach for identifying attacks and proposing countermeasures against the exploitation of vulnerabilities in a system . This paper describes an extension of Cloud Privacy Threat Modeling (CPTM) methodology for privacy threat modeling in relation to processing sensitive data in cloud computing environments. It describes the modeling methodology that involved applying Method Engineering to specify characteristics of a cloud privacy threat modeling methodology, different steps in the proposed methodology and corresponding products. In addition, a case study has been implemented as a proof of concept to demonstrate the usability of the proposed methodology. We believe that the extended…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
