vix.ing · top · new · best · stats · spec

A Logical Framework for Verifying Privacy Breaches of Social Networks

2018/06/09 by Néstor Cataño, Cataño, Néstor
Computer Science · Social Sciences · #Access Control and Trust #Cryptography and Data Security #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting #Software Engineering (cs.SE) #cs.CR #cs.SE

paper · pdf · doi:10.48550/arxiv.1806.03519

32 pages

arxiv created 2018/06/09 · openalex publication_date 2018/06/09 · arxiv updated 2018/06/12 · openalex created_date 2018/06/13 · openalex updated_date 2026/07/28

Abstract

We present a novel approach to deal with transitivity permission-delegation threats that arise in social networks when content is granted permissions by third-party users thereby breaking the privacy policy of the content owner. These types of privacy breaches are often unintentional in social networks like Facebook, and hence, (more) in-place mechanisms are needed to make social network users aware of the consequences of changing their privacy policies. Our approach is unique in its use of formal methods tools and techniques. It builds on a predicate logic definition for social networking that caters for common aspects of existing social networks such as users, social network content, friendship, permissions over content, and content transmission. Our approach is implemented in Yices. For the predicate logic model, we formulate a security policy for the verification of the permission flow of content owned by social network users and demonstrate how this security policy can be verified.

Related