Cargando…

PRASH: A Framework for Privacy Risk Analysis of Smart Homes

Smart homes promise to improve the quality of life of residents. However, they collect vasts amounts of personal and sensitive data, making privacy protection critically important. We propose a framework, called PRASH, for modeling and analyzing the privacy risks of smart homes. It is composed of th...

Descripción completa

Detalles Bibliográficos
Autores principales: Bugeja, Joseph, Jacobsson, Andreas, Davidsson, Paul
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8512241/
https://www.ncbi.nlm.nih.gov/pubmed/34640718
http://dx.doi.org/10.3390/s21196399
_version_ 1784582943831752704
author Bugeja, Joseph
Jacobsson, Andreas
Davidsson, Paul
author_facet Bugeja, Joseph
Jacobsson, Andreas
Davidsson, Paul
author_sort Bugeja, Joseph
collection PubMed
description Smart homes promise to improve the quality of life of residents. However, they collect vasts amounts of personal and sensitive data, making privacy protection critically important. We propose a framework, called PRASH, for modeling and analyzing the privacy risks of smart homes. It is composed of three modules: a system model, a threat model, and a set of privacy metrics, which together are used for calculating the privacy risk exposure of a smart home system. By representing a smart home through a formal specification, PRASH allows for early identification of threats, better planning for risk management scenarios, and mitigation of potential impacts caused by attacks before they compromise the lives of residents. To demonstrate the capabilities of PRASH, an executable version of the smart home system configuration was generated using the proposed formal specification, which was then analyzed to find potential attack paths while also mitigating the impacts of those attacks. Thereby, we add important contributions to the body of knowledge on the mitigations of threat agents violating the privacy of users in their homes. Overall, the use of PRASH will help residents to preserve their right to privacy in the face of the emerging challenges affecting smart homes.
format Online
Article
Text
id pubmed-8512241
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-85122412021-10-14 PRASH: A Framework for Privacy Risk Analysis of Smart Homes Bugeja, Joseph Jacobsson, Andreas Davidsson, Paul Sensors (Basel) Article Smart homes promise to improve the quality of life of residents. However, they collect vasts amounts of personal and sensitive data, making privacy protection critically important. We propose a framework, called PRASH, for modeling and analyzing the privacy risks of smart homes. It is composed of three modules: a system model, a threat model, and a set of privacy metrics, which together are used for calculating the privacy risk exposure of a smart home system. By representing a smart home through a formal specification, PRASH allows for early identification of threats, better planning for risk management scenarios, and mitigation of potential impacts caused by attacks before they compromise the lives of residents. To demonstrate the capabilities of PRASH, an executable version of the smart home system configuration was generated using the proposed formal specification, which was then analyzed to find potential attack paths while also mitigating the impacts of those attacks. Thereby, we add important contributions to the body of knowledge on the mitigations of threat agents violating the privacy of users in their homes. Overall, the use of PRASH will help residents to preserve their right to privacy in the face of the emerging challenges affecting smart homes. MDPI 2021-09-25 /pmc/articles/PMC8512241/ /pubmed/34640718 http://dx.doi.org/10.3390/s21196399 Text en © 2021 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Bugeja, Joseph
Jacobsson, Andreas
Davidsson, Paul
PRASH: A Framework for Privacy Risk Analysis of Smart Homes
title PRASH: A Framework for Privacy Risk Analysis of Smart Homes
title_full PRASH: A Framework for Privacy Risk Analysis of Smart Homes
title_fullStr PRASH: A Framework for Privacy Risk Analysis of Smart Homes
title_full_unstemmed PRASH: A Framework for Privacy Risk Analysis of Smart Homes
title_short PRASH: A Framework for Privacy Risk Analysis of Smart Homes
title_sort prash: a framework for privacy risk analysis of smart homes
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8512241/
https://www.ncbi.nlm.nih.gov/pubmed/34640718
http://dx.doi.org/10.3390/s21196399
work_keys_str_mv AT bugejajoseph prashaframeworkforprivacyriskanalysisofsmarthomes
AT jacobssonandreas prashaframeworkforprivacyriskanalysisofsmarthomes
AT davidssonpaul prashaframeworkforprivacyriskanalysisofsmarthomes