The security cost of cheap user interaction

The security cost of cheap user interaction
复制标题

廉价用户交互的安全成本

DOI:
--
复制
发表时间:
2011
期刊:
New Security Paradigms Workshop
影响因子:
--
通讯作者:
Jens Grossklags
Jens Grossklags
中科院分区:
--
文献类型:
--
作者:
Rainer Böhme;Jens Grossklags

文献摘要

被引文献

相似文献

人类注意力是一种稀缺资源,缺乏注意力可能会导致严重的安全漏洞。由于大多数安全技术都依赖于某种方式的周到的人为干预,因此应该经济地消耗这一资源。在这种情况下,我们假设这样的观点:每一个误报或不必要的用户交互都会对这块注意力的所有其他潜在消费者产生负外部性。该论文指出了在安全应用中刺激人类注意力过度消耗的激励问题。它进一步概述了在行为科学的既定理论背景下设计的注意力集中模型,并讨论了解决安全通知中的错误分配问题的激励机制,例如对注意力消耗征收庇古税的想法。
Human attention is a scarce resource, and lack thereof can cause severe security breaches. As most security techniques rely on considerate human intervention in one way or another, this resource should be consumed economically. In this context, we postulate the view that every false alarm or unnecessary user interaction imposes a negative externality on all other potential consumers of this chunk of attention. The paper identifies incentive problems that stimulate overconsumption of human attention in security applications. It further outlines a lump-of-attention model, devised against the backdrop of established theories in the behavioral sciences, and discusses incentive mechanisms to fix the misallocation problem in security notification, for instance the idea of a Pigovian tax on attention consumption.