Table of Contents
Fetching ...

PTMF: A Privacy Threat Modeling Framework for IoT with Expert-Driven Threat Propagation Analysis

Emmanuel Dare Alalade, Ashraf Matrawy

TL;DR

PTMF introduces a privacy-centric framework that combines MITRE ATT&CK tactics with LINDDUN PRO techniques to analyze IoT privacy threats via threat actors, surfaces, entry points, propagation, and outcomes. The authors validate PTMF through an expert-driven user study (n≈20) that maps threat actors to techniques and identifies key threat paths, highlighting cloud providers, service providers, and insiders as top actors. The work contributes a novel framework, systematic actor characterization, and rich visualizations (heatmaps, network graphs) to guide privacy-preserving controls and IoT risk assessment. It lays groundwork for automated privacy threat analysis tools and proactive PPT deployment in IoT ecosystems.

Abstract

Previous studies on PTA have focused on analyzing privacy threats based on the potential areas of occurrence and their likelihood of occurrence. However, an in-depth understanding of the threat actors involved, their actions, and the intentions that result in privacy threats is essential. In this paper, we present a novel Privacy Threat Model Framework (PTMF) that analyzes privacy threats through different phases. The PTMF development is motivated through the selected tactics from the MITRE ATT\&CK framework and techniques from the LINDDUN privacy threat model, making PTMF a privacy-centered framework. The proposed PTMF can be employed in various ways, including analyzing the activities of threat actors during privacy threats and assessing privacy risks in IoT systems, among others. In this paper, we conducted a user study on 12 privacy threats associated with IoT by developing a questionnaire based on PTMF and recruited experts from both industry and academia in the fields of security and privacy to gather their opinions. The collected data were analyzed and mapped to identify the threat actors involved in the identification of IoT users (IU) and the remaining 11 privacy threats. Our observation revealed the top three threat actors and the critical paths they used during the IU privacy threat, as well as the remaining 11 privacy threats. This study could provide a solid foundation for understanding how and where privacy measures can be proactively and effectively deployed in IoT systems to mitigate privacy threats based on the activities and intentions of threat actors within these systems.

PTMF: A Privacy Threat Modeling Framework for IoT with Expert-Driven Threat Propagation Analysis

TL;DR

PTMF introduces a privacy-centric framework that combines MITRE ATT&CK tactics with LINDDUN PRO techniques to analyze IoT privacy threats via threat actors, surfaces, entry points, propagation, and outcomes. The authors validate PTMF through an expert-driven user study (n≈20) that maps threat actors to techniques and identifies key threat paths, highlighting cloud providers, service providers, and insiders as top actors. The work contributes a novel framework, systematic actor characterization, and rich visualizations (heatmaps, network graphs) to guide privacy-preserving controls and IoT risk assessment. It lays groundwork for automated privacy threat analysis tools and proactive PPT deployment in IoT ecosystems.

Abstract

Previous studies on PTA have focused on analyzing privacy threats based on the potential areas of occurrence and their likelihood of occurrence. However, an in-depth understanding of the threat actors involved, their actions, and the intentions that result in privacy threats is essential. In this paper, we present a novel Privacy Threat Model Framework (PTMF) that analyzes privacy threats through different phases. The PTMF development is motivated through the selected tactics from the MITRE ATT\&CK framework and techniques from the LINDDUN privacy threat model, making PTMF a privacy-centered framework. The proposed PTMF can be employed in various ways, including analyzing the activities of threat actors during privacy threats and assessing privacy risks in IoT systems, among others. In this paper, we conducted a user study on 12 privacy threats associated with IoT by developing a questionnaire based on PTMF and recruited experts from both industry and academia in the fields of security and privacy to gather their opinions. The collected data were analyzed and mapped to identify the threat actors involved in the identification of IoT users (IU) and the remaining 11 privacy threats. Our observation revealed the top three threat actors and the critical paths they used during the IU privacy threat, as well as the remaining 11 privacy threats. This study could provide a solid foundation for understanding how and where privacy measures can be proactively and effectively deployed in IoT systems to mitigate privacy threats based on the activities and intentions of threat actors within these systems.
Paper Structure (34 sections, 18 figures, 1 table)

This paper contains 34 sections, 18 figures, 1 table.

Figures (18)

  • Figure 1: Privacy Threat Modeling Framework (PTMF)
  • Figure 2: Methodological Workflow for the user study process and evaluation of the activities of threat actors responsible for privacy threats in IoT systems
  • Figure 3: The variation in the number of participants for each privacy threat
  • Figure 4: Highlight in red box the progression of threat actors' activities from initial attack vectors through system infiltration to the compromise and misuse of sensitive information.
  • Figure 5: Frequency of privacy threat techniques used by different threat actors. The heatmap illustrates various techniques (x-axis), categorized by threat tactics, versus the type of threat actor (y-axis). The color intensity of each cell, along with its numerical value, represents the frequency with which a specific actor is likely to employ a given technique.
  • ...and 13 more figures