Measuring Security Practices and How They Impact Security

Measuring Security Practices and How They Impact Security
复制标题

衡量安全实践及其对安全的影响

DOI:
10.1145/3355369.3355571
复制
发表时间:
2019
期刊:
Proceedings of the Internet Measurement Conference (IMC'19
影响因子:
--
通讯作者:
Savage, Stefan
Savage, Stefan
中科院分区:
--
文献类型:
--
作者:
DeKoven, Louis F.;Randall, Audrey;Mirian, Ariana;Akiwate, Gautam;Blume, Ansel;Saul, Lawrence K.;Schulman, Aaron;Voelker, Geoffrey M.;Savage, Stefan

文献摘要

参考文献

被引文献

相似文献

安全是一门对外行用户寄予厚望的学科。因此,我们建议最终用户采用大量的技术和行为,从而降低他们的安全风险。然而,采用这些“最佳实践”——从使用防病毒产品到积极保持软件更新——并没有得到很好的理解,它们对安全风险的实际影响也没有得到很好的确认。本文通过在六个月内覆盖约15,000台计算机的大规模实证测量研究探讨了这两个问题。我们使用被动监测来推断和描述各种安全实践的流行情况,以及一系列其他潜在的安全相关行为。然后,我们探讨了关键安全行为的差异对现实世界结果的影响程度(即,设备显示出已被破坏的明确证据)。
Security is a discipline that places significant expectations on lay users. Thus, there are a wide array of technologies and behaviors that we exhort end users to adopt and thereby reduce their security risk. However, the adoption of these "best practices" --- ranging from the use of antivirus products to actively keeping software updated --- is not well understood, nor is their practical impact on security risk well-established. This paper explores both of these issues via a large-scale empirical measurement study covering approximately 15,000 computers over six months. We use passive monitoring to infer and characterize the prevalence of various security practices in situ as well as a range of other potentially security-relevant behaviors. We then explore the extent to which differences in key security behaviors impact real-world outcomes (i.e., that a device shows clear evidence of having been compromised).
恶意软件感染相关危险因素的临床研究
DOI: --
发表时间: 2013
期刊: Conference on Computer and Communications Security
影响因子: --
作者:
F. Lévesque;J. Nsiempba;José M. Fernandez;Sonia Chiasson;Anil Somayaji
通讯作者: Anil Somayaji
做或不做,没有尝试:用户参与可能不会改善安全结果
DOI: --
发表时间: 2016
期刊: Symposium On Usable Privacy and Security
影响因子: --
作者:
Alain Forget;Sarah Pearman;Jeremy Thomas;A. Acquisti;Nicolas Christin;L. Cranor;Serge Egelman;Marian Harbach;Rahul Telang
通讯作者: Rahul Telang
聚集脆弱的猫:一种统计方法来消除共享托管中网络安全的共同责任
DOI: 10.1145/3133956.3133971
发表时间: 2017
期刊: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Samaneh Tajalizadehkhoob;Tom van Goethem;Maciej Korczyński;Arman Noroozian;Rainer Böhme;T. Moore;W. Joosen;M. V. Eeten
通讯作者: M. V. Eeten
基于客户网络使用情况的计算机感染风险因素分析
DOI: --
发表时间: 2008
期刊: 2008 Second International Conference on Emerging Security Information, Systems and Technologies
影响因子: --
作者:
Y. Carlinet;L. Mé;Hervé Debar;Y. Gourhant
通讯作者: Y. Gourhant
我如何学会安全:对安全建议来源和行为的人口普查代表性调查
DOI: 10.1145/2976749.2978307
发表时间: 2016
期刊: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security
影响因子: --
作者:
Elissa M. Redmiles;Sean Kross;Michelle L. Mazurek
通讯作者: Michelle L. Mazurek