Valuing information security from a phishing attack

Valuing information security from a phishing attack
复制标题

重视网络钓鱼攻击的信息安全

DOI:
--
复制
发表时间:
2017
影响因子:
3.9
通讯作者:
R. John
R. John
中科院分区:
--
文献类型:
--
作者:
Kenneth D. Nguyen;Heather Rosoff;R. John

文献摘要

被引文献

相似文献

在大多数网络安全环境中,用户需要为信息安全做出权衡。本研究通过在包含多个相互冲突的目标的价值体系中量化信息安全的相对价值来检验这个问题。本研究亦以此量化为平台,检视不同使用情境对资讯安全关注的影响。用户被要求指出在生产力和时间上损失了多少,以及他们愿意花多少钱来购买一个有效的网络钓鱼过滤器。结果表明,用户优先考虑生产力和时间而不是信息安全,而在关注成本方面存在更多的异质性。在不同的使用环境中,信息安全的价值差异不显著。信息安全的相对价值可以预测自我报告的网络安全行为。这些结果为设计更可用的信息安全系统提供了有价值的启示。
In most cyber security contexts, users need to make trade-offs for information security. This research examined this issue by quantifying the relative value of information security within a value system that comprises of multiple conflicting objectives. Using this quantification as a platform, this research also examined the effect of different usage contexts on information security concern. Users were asked to indicate how much loss in productivity and time, and how much more money they were willing to incur to acquire an effective phishing filter. The results indicated that users prioritize productivity and time over information security while there was much more heterogeneity in the concern about cost. The value of information security was insignificantly different across different usage contexts. The relative value of information security was found to be predictive of self-reported online security behaviors. These results offer valuable implications for the design of a more usable information security system.