Hanaa Alshareef

dblp:268/5291 · DBLP profile ↗
← Back
4ranked-venue papers
4as first author
3since 2021 · last 2022
0000-0002-0338-2839ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 3 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2022 Precise Analysis of Purpose Limitation in Data Flow Diagrams
abstract
Data Flow Diagrams (DFDs) are primarily used for modelling functional properties of a system. In recent work, it was shown that DFDs can be used to also model non-functional properties, such as security and privacy properties, if they are annotated with appropriate security- and privacy-related information. An important privacy principle one may wish to model in this way is purpose limitation. But previous work on privacy-aware DFDs (PA-DFDs) considers purpose limitation only superficially, without explaining how the purpose of DFD activators and flows ought to be specified, checked or inferred. In this paper, we define a rigorous formal framework for (1) annotating DFDs with purpose labels and privacy signatures, (2) checking the consistency of labels and signatures, and (3) inferring labels from signatures. We implement our theoretical framework in a proof-of concept tool consisting of a domain-specific language (DSL) for specifying privacy signatures and algorithms for checking and inferring purpose labels from such signatures. Finally, we evaluate our framework and tool through a case study based on a DFD from the privacy literature.
Hanaa Alshareef, Katja Tuma, Sandro Stucki, Gerardo Schneider, Riccardo Scandariato
ARES1
2021 Transforming Data Flow Diagrams for Privacy Compliance
abstract
Most software design tools, as for instance Data Flow Diagrams (DFDs), are focused on functional aspects and cannot thus model non-functional aspects like privacy. In this paper, we provide an explicit algorithm and a proof-of-concept implementation to transform DFDs into so-called Privacy-Aware Data Flow Diagrams (PA-DFDs). Our tool systematically inserts privacy checks to a DFD, generating a PA-DFD. We apply our approach to two realistic applications from the construction and online retail sectors.
Hanaa Alshareef, Sandro Stucki, Gerardo Schneider
MODELSWARD1
2021 Refining Privacy-Aware Data Flow Diagrams
Hanaa Alshareef, Sandro Stucki, Gerardo Schneider
SEFM1
2020 A collaborative access control framework for online social networks
Hanaa Alshareef, Raúl Pardo, Gerardo Schneider, Pablo Picazo-Sanchez
J. Log. Algebraic Methods Program.1