How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and Behavior

How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and Behavior
复制标题

我如何学会安全:对安全建议来源和行为的人口普查代表性调查

DOI:
10.1145/2976749.2978307
复制
发表时间:
2016
期刊:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Michelle L. Mazurek
Michelle L. Mazurek
中科院分区:
--
文献类型:
--
作者:
Elissa M. Redmiles;Sean Kross;Michelle L. Mazurek

文献摘要

被引文献

相似文献

很少有用户拥有可以请求数字安全建议的单一权威来源。相反,数字安全技能通常是偶然学习的,因为用户会过滤大量的安全建议。通过了解影响用户建议来源、信念和安全行为的因素,我们可以帮助减少向用户提供建议的数量并提高质量,简化学习关键行为的过程。本文严格调查了用户的安全信念、知识和人口统计数据与其安全建议来源的关系,以及所有这些因素如何影响安全行为。通过对 526 名用户进行仔细预先测试的美国人口普查代表调查,我们概述了受访者建议来源的普遍性、接受和拒绝这些来源建议的原因,以及这些来源和人口统计因素对安全行为的影响。我们发现安全领域存在“数字鸿沟”的证据:技能水平和社会经济地位较高的用户的建议来源与资源较少的用户不同。这种数字安全鸿沟可能会加剧本已处于不利地位的用户的脆弱性。此外,我们确认并扩展了之前小样本研究的结果,即为什么用户接受某些数字安全建议(例如,因为他们信任来源而不是内容)并拒绝其他建议(例如,因为它不方便并且因为它包含太多营销材料)。最后,我们提出了消除数字鸿沟和提高数字安全建议有效性的建议。
Few users have a single, authoritative, source from whom they can request digital-security advice. Rather, digital-security skills are often learned haphazardly, as users filter through an overwhelming quantity of security advice. By understanding the factors that contribute to users' advice sources, beliefs, and security behaviors, we can help to pare down the quantity and improve the quality of advice provided to users, streamlining the process of learning key behaviors. This paper rigorously investigates how users' security beliefs, knowledge, and demographics correlate with their sources of security advice, and how all these factors influence security behaviors. Using a carefully pre-tested, U.S.-census-representative survey of 526 users, we present an overview of the prevalence of respondents' advice sources, reasons for accepting and rejecting advice from those sources, and the impact of these sources and demographic factors on security behavior. We find evidence of a "digital divide" in security: the advice sources of users with higher skill levels and socioeconomic status differ from those with fewer resources. This digital security divide may add to the vulnerability of already disadvantaged users. Additionally, we confirm and extend results from prior small-sample studies about why users accept certain digital-security advice (e.g., because they trust the source rather than the content) and reject other advice (e.g., because it is inconvenient and because it contains too much marketing material). We conclude with recommendations for combating the digital divide and improving the efficacy of digital-security advice.