Stories as informal lessons about security

Stories as informal lessons about security
复制标题

故事作为有关安全的非正式课程

DOI:
--
复制
发表时间:
2012
期刊:
Symposium On Usable Privacy and Security
影响因子:
--
通讯作者:
Brandon Brooks
Brandon Brooks
中科院分区:
--
文献类型:
--
作者:
E. Rader;Rick Wash;Brandon Brooks

文献摘要

被引文献

相似文献

非专家计算机用户经常需要做出与安全相关的决策;然而,这些决定往往不是特别好或复杂。然而,他们的选择并不是随机的。这些非专家做出决策所依据的信息来自哪里?我们认为,这些信息大部分来自他们从其他人那里听到的故事。我们进行了一项调查,就人们从他人那里听到的安全故事提出开放式和封闭式问题。我们发现大多数人都从家人和朋友非正式的安全事件故事中吸取了教训。这些故事影响人们对安全的思考方式,以及他们在做出安全相关决策时的后续行为。此外,许多人向其他人复述这些故事,这表明一个故事有可能影响多人。了解非专家如何从故事中学习,以及他们从哪些类型的故事中学习,可以帮助我们找出新方法来帮助这些人做出更好的安全决策。
Non-expert computer users regularly need to make security-relevant decisions; however, these decisions tend not to be particularly good or sophisticated. Nevertheless, their choices are not random. Where does the information come from that these non-experts base their decisions upon? We argue that much of this information comes from stories they hear from other people. We conducted a survey to ask open- and closed- ended questions about security stories people hear from others. We found that most people have learned lessons from stories about security incidents informally from family and friends. These stories impact the way people think about security, and their subsequent behavior when making security-relevant decisions. In addition, many people retell these stories to others, indicating that a single story has the potential to influence multiple people. Understanding how non-experts learn from stories, and what kinds of stories they learn from, can help us figure out new methods for helping these people make better security decisions.