User Privacy Risk Analysis For The Internet of Things

Akash Aggarwal, Waqar Asif, Habibul Azam, Milan Marković, Muttukrishnan Rajarajan, Peter J. Edwards · 2019

The Internet of Things (IoT) refers to a large network of devices such as sensors and actuators in which diverse types of data is generated and shared. Data can be shared in its raw form or as a result of data processing activities performed by an IoT device (e.g. anonymization, aggregation, etc.). However, sharing such data introduces a multitude of risks which are influenced by data type, data harvesting granularity, user demographics and the device under consideration. In this work, we propose a novel extension to our attack tree risk model [1] to consider user preferences for sharing personal data. We enrich our earlier work by exploring more attacks and complimenting them with a user privacy-risk model. We evaluate this proposed model and identify a range of scenarios which can result in personal information privacy violation and thus provide a model for estimating the potential risk of an IoT ecosystem.

Read the paper · More papers on PaperTik