Do or Do Not, There Is No Try: User Engagement May Not Improve Security Outcomes
Do or Do Not, There Is No Try: User Engagement May Not Improve Security Outcomes
复制标题
做或不做,没有尝试:用户参与可能不会改善安全结果
DOI:
--
复制
发表时间:
2016
期刊:
影响因子:
--
通讯作者:
Rahul Telang
中科院分区:
文献类型:
--
作者:
Alain Forget;Sarah Pearman;Jeremy Thomas;A. Acquisti;Nicolas Christin;L. Cranor;Serge Egelman;Marian Harbach;Rahul Telang
Computer security problems often occur when there are disconnects between users’ understanding of their role in computer security and what is expected of them. To help users make good security decisions more easily, we need insights into the challenges they face in their daily computer usage. We built and deployed the Security Behavior Observatory (SBO) to collect data on user behavior and machine configurations from participants’ home computers. Combining SBO data with user interviews, this paper presents a qualitative study comparing users’ attitudes, behaviors, and understanding of computer security to the actual states of their computers. Qualitative inductive thematic analysis of the interviews produced “engagement” as the overarching theme, whereby participants with greater engagement in computer security and maintenance did not necessarily have more secure computer states. Thus, user engagement alone may not be predictive of computer security. We identify several other themes that inform future directions for better design and research into security interventions. Our findings emphasize the need for better understanding of how users’ computers get infected, so that we can more effectively design user-centered mitigations.