Eye tracking analysis of browser security indicators

Eye tracking analysis of browser security indicators
复制标题

浏览器安全指标眼动追踪分析

DOI:
10.1109/iccsii.2012.6454330
复制
发表时间:
2012
期刊:
2012 International Conference on Computer Systems and Industrial Informatics
影响因子:
--
通讯作者:
Emad Bataineh
Emad Bataineh
中科院分区:
--
文献类型:
--
作者:
A. Darwish;Emad Bataineh

文献摘要

被引文献

相似文献

理解人们与Web浏览器交互时的自然人类行为对于构建基于用户感知和体验定制的以用户为中心的界面设计至关重要。本文提出了第一个实证研究用户的互动与安全指标在Web浏览器中的控制真实的生活安全风险。这项工作的重点是自然和自发的行为,受害者的眼睛在几个预定的兴趣领域,并经验地提出了用户的评价几个在线登录页面。实验结果为IE8浏览器中视觉安全指示器的可用性提供了量化的证据。我们首先对一组网站进行分类,并使用最常见的钓鱼技术创建钓鱼网页,然后在眼动仪上对来自不同背景和年龄组的一组用户进行控制实验。我们发现,网页设计中的简单方法会造成更多的损害,而不是帮助在线安全,并且当前圆滑的网页设计会帮助用户找到登录区域,而忽略安全指示器。我们还发现,参与者没有使用安全证书提示来确定所呈现网站的合法性。
Understanding the natural human behavior when people interact with Web browsers is essential for building more user-centric interface design that is customized based on user's perception and experience. This paper presents the first empirical study of users' interaction with security indicators in Web browsers in a controlled real life security risk. The work focuses on the natural and spontaneous behavior of the victim's eyes on several predetermined area of interest, and empirically presents users' evaluation of several online logon pages. The experiment and its results provide a quantitative evidence of the usability of visual security indicators in Internet Explorer (IE8). We first categorized a set of Websites and created phishing Web Pages using most known phishing techniques, and then a group of users from different backgrounds and age groups took the controlled experiment on an eye tracking machine. We found that the simplicity approach in Web design causes more damage rather than helping in online security, and that the current sleek design of Web pages helps users find the logon area and overlook the security indicators instead. We also found that the security certificate cue was not used by the participants to determine the legitimacy of the presented Websites.