Western University Scholarship@Western Electronic Thesis and Dissertation Repository 12-18-2020 10:45 AM Protecting Health Data in a Pandemic: A Systematic Adversarial Threat Analysis of Contact Tracing Apps Leah Krehling, The University of Western Ontario Supervisor: Essex, Aleksander, The University of Western Ontario A thesis submitted in partial fulfillment of the equirr ements for the Master of Engineering Science degree in Electrical and Computer Engineering © Leah Krehling 2020 Follow this and additional works at: https://ir.lib.uwo.ca/etd Part of the Other Electrical and Computer Engineering Commons Recommended Citation Krehling, Leah, "Protecting Health Data in a Pandemic: A Systematic Adversarial Threat Analysis of Contact Tracing Apps" (2020). Electronic Thesis and Dissertation Repository. 7586. https://ir.lib.uwo.ca/etd/7586 This Dissertation/Thesis is brought to you for free and open access by Scholarship@Western. It has been accepted for inclusion in Electronic Thesis and Dissertation Repository by an authorized administrator of Scholarship@Western. For more information, please contact
[email protected]. Abstract In this thesis centralized, decentralized, Bluetooth, and GPS based applications of digital contact tracing were reviewed and assessed. Using privacy principles created by a contingent of security and privacy experts from across Canada, a metric of assessing an application’s privacy was created. An attack tree was built to assess the security of the contact tracing applications. Eighteen attacks were theorized against contact tracing applications currently in use. An application’s vulnerability to the attacks was measured using a scoring system developed for this purpose. The results of the security scores were used to create a metric for assessing the security of contact tracing systems.