Enhancing User Privacy Protection by Enforcing Clark-Wilson Security Model on Facebook

Francis Avorgbedor,Jigang Liu
DOI: https://doi.org/10.1109/eit48999.2020.9208279
2020-07-01
Abstract:As Facebook becomes one of the most popular social media platforms, it has been sued by numerous privacy violations, notably the Cambridge Analytica scandal, reported in March 2018, where 87 million Facebook users' personal data were exposed and used for political purposes. This project aims to improve the Facebook user privacy control by enforcing Clark-Wilson (CW) security model. First, the Facebook privacy policy is reviewed and analyzed by categorizing it into major components and then the elements that contribute to high rate of user privacy and integrity threats are identified with the evaluation in relation to enforcement of user privacy integrity. Next, based on the identified limitations of existing measures that have been implemented to protect user privacy and data integrity, a new framework, known as I4A (Integrity, Audit, Authorization, Authentication and Access control), is proposed. This new framework provides a constructive enforcement of the privacy policy on Facebook by applying Clark-Wilson (CW) security model in which the Enforcement Rules (ERs) and Clarification Rules (CRs) are imposed to identify, verify and evaluate data integrity threats in privacy settings. Last, through comprehensive case studies, the new framework has demonstrated its potential in minimizing unnecessary disclosure of user's private information as well as in preventing excessive data mining by third party apps on Facebook.
What problem does this paper attempt to address?