Do or Do Not, There Is No Try: User Engagement May Not Improve Security Outcomes

Do or Do Not, There Is No Try: User Engagement May Not Improve Security Outcomes
复制标题

做或不做,没有尝试:用户参与可能不会改善安全结果

DOI:
--
复制
发表时间:
2016
期刊:
Symposium On Usable Privacy and Security
影响因子:
--
通讯作者:
Rahul Telang
Rahul Telang
中科院分区:
--
文献类型:
--
作者:
Alain Forget;Sarah Pearman;Jeremy Thomas;A. Acquisti;Nicolas Christin;L. Cranor;Serge Egelman;Marian Harbach;Rahul Telang

文献摘要

被引文献

相似文献

当用户对自身在计算机安全中所扮演角色的理解与其被期望的行为之间存在脱节时,计算机安全问题就常常会出现。为了帮助用户更轻松地做出良好的安全决策,我们需要深入了解他们在日常使用计算机时所面临的挑战。我们构建并部署了安全行为观测站(SBO),以便从参与者的家用计算机中收集有关用户行为和机器配置的数据。将SBO数据与用户访谈相结合,本文进行了一项定性研究,将用户对计算机安全的态度、行为和理解与其计算机的实际状态进行了比较。对访谈进行的定性归纳主题分析得出“参与度”这一首要主题,即对计算机安全和维护参与度更高的参与者,其计算机状态不一定更安全。因此,仅用户参与度可能无法预测计算机安全状况。我们还确定了其他几个主题,这些主题为未来更好地设计和研究安全干预措施指明了方向。我们的研究结果强调,需要更好地了解用户的计算机是如何被感染的,这样我们才能更有效地设计以用户为中心的缓解措施。
Computer security problems often occur when there are disconnects between users’ understanding of their role in computer security and what is expected of them. To help users make good security decisions more easily, we need insights into the challenges they face in their daily computer usage. We built and deployed the Security Behavior Observatory (SBO) to collect data on user behavior and machine configurations from participants’ home computers. Combining SBO data with user interviews, this paper presents a qualitative study comparing users’ attitudes, behaviors, and understanding of computer security to the actual states of their computers. Qualitative inductive thematic analysis of the interviews produced “engagement” as the overarching theme, whereby participants with greater engagement in computer security and maintenance did not necessarily have more secure computer states. Thus, user engagement alone may not be predictive of computer security. We identify several other themes that inform future directions for better design and research into security interventions. Our findings emphasize the need for better understanding of how users’ computers get infected, so that we can more effectively design user-centered mitigations.