The Good, the Bad and the Ugly: A Study of Security Decisions in a Cyber-Physical Systems Game

The Good, the Bad and the Ugly: A Study of Security Decisions in a Cyber-Physical Systems Game
复制标题

好、坏、丑:网络物理系统博弈中安全决策的研究

DOI:
10.1109/tse.2017.2782813
复制
发表时间:
2019
影响因子:
7.4
通讯作者:
Frey S
Frey S
中科院分区:
计算机科学1区
文献类型:
--
作者:
Frey S

文献摘要

参考文献

被引文献

相似文献

利益相关者的安全决策在确定安全需求方面发挥着至关重要的作用,然而,目前人们对组织内不同的利益相关者群体如何处理安全以及支撑他们决策的驱动因素和默契偏见知之甚少。在玩我们设计和开发的桌面游戏时,我们研究并对比了三个人群--安全专家、计算机科学家和经理--的安全决策。这款游戏的任务是让玩家在面临各种威胁的同时管理网络物理环境的安全。对12组玩家(在我们的人口统计数据中每组4组)的分析揭示了重复特定人口统计数据的策略,例如,经理和安全专家通常更喜欢技术解决方案,而不是人员培训,这是计算机科学家更喜欢的。令人惊讶的是,安全专家本身并不是更好的参与者--在某些情况下,他们做出了非常有问题的决定--但他们对自己表现出了更高的信心。我们对玩家的决策过程进行了分类,即程序驱动、经验驱动、场景驱动或直觉驱动。我们确定了决策模式,既有良好的实践,也有典型的错误和陷阱。我们的游戏提供了一个需求沙盒,玩家可以在其中试验安全风险,了解决策及其后果,并反思自己对安全的看法。
Stakeholders' security decisions play a fundamental role in determining security requirements, yet, little is currently understood about how different stakeholder groups within an organisation approach security and the drivers and tacit biases underpinning their decisions. We studied and contrasted the security decisions of three demographics-security experts, computer scientists and managers-when playing a tabletop game that we designed and developed. The game tasks players with managing the security of a cyber-physical environment while facing various threats. Analysis of 12 groups of players (4 groups in each of our demographics) reveals strategies that repeat in particular demographics, e.g., managers and security experts generally favoring technological solutions over personnel training, which computer scientists preferred. Surprisingly, security experts were not ipso facto better players-in some cases, they made very questionable decisions-yet they showed a higher level of confidence in themselves. We classified players' decision-making processes, i.e., procedure-, experience-, scenario- or intuition-driven. We identified decision patterns, both good practices and typical errors and pitfalls. Our game provides a requirements sandbox in which players can experiment with security risks, learn about decision-making and its consequences, and reflect on their own perception of security.
当今控制系统的安全状况
DOI: --
发表时间: 2015
期刊:
影响因子: --
作者:
D. Harp;Extra Slides
通讯作者: Extra Slides
信息安全和隐私的有效管理。
DOI: --
发表时间: 2006
期刊:
影响因子: --
作者:
Alicia Anderson
通讯作者: Alicia Anderson
DOI: 10.1207/s15516709cog1804_1
发表时间: 1994-10-01
期刊: COGNITIVE SCIENCE
影响因子: 2.5
作者:
KIRSH, D;MAGLIO, P
通讯作者: MAGLIO, P
DOI: --
发表时间: 2014
期刊: IEEE International Requirements Engineering Conference
影响因子: --
作者:
M. Pinto;A. Rashid
通讯作者: A. Rashid
发展扎根理论的定性研究技术和程序的基础知识回顾(第二版)
DOI: --
发表时间: 1999
期刊:
影响因子: --
作者:
D. Francis
通讯作者: D. Francis