TC: Small: Effective Security Warning Dialogs
TC:小:有效的安全警告对话框
基本信息
- 批准号:1116934
- 负责人:
- 金额:$ 50万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2011
- 资助国家:美国
- 起止时间:2011-09-01 至 2015-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
This project focuses on improving the effectiveness of computer security warning dialogs ? on-screen prompts that warn users about a potential security risks and give users a choice between two or more courses of action. Security dialogs should help users avoid unsafe actions while allowing them to take safe actions by presenting information that allows users to make informed decisions that the system cannot make with user input. This research takes a novel approach to the design and rigorous evaluation of computer security warning dialogs, with the goal of developing generalizable guidelines for designing effective warning dialogs for software products. This has the potential to help end users make better security decisions that keep their information and computer systems safer, and improve the computer security ecosystem.Based on the Carnegie-Mellon team?s previous work, review of the literature, and discussions with collaborators, they have developed a set of candidate features that will have a significant impact on the effectiveness of security dialogs. For example, these features include: amount and placemen of text, severity of tone, how to help users decide, describing risks and consequences, use of recommended and default options, and more. They plan to systematically study each feature, applied to a variety of security dialogs, to determine the impact of each (individually and in combination) and to develop guidelines on how to use each feature to best effect. They will follow an iterative design and evaluation approach that will involve five types of studies: exploratory interviews, Mechanical Turk studies, laboratory studies, field studies, and interface designer studies. In the Mechanical Turk studies, participants will be provided with a scenario and a security dialog triggered by that scenario and asked how they would be most likely to respond. They will also be asked follow-up questions to learn why they made that decision, their perception of the risks associated with each warning dialog, their understanding of the warning dialog, their beliefs about how well they think they understand the warning dialog, and their knowledge of the concepts and vocabulary included in each dialog. We will measure the tendency for users to take the recommended action in risky scenarios and the non-recommended action in benign scenarios. The follow-up questions will help determine why users behave the way they do and how to most effectively design security warning dialogs to influence that behavior. It is important to determine how to communicate effectively about the risks and consequences, but also to determine how much users need to be able to understand before they make appropriate decisions. It is anticipated that of some aspects of the situation will be correlated with behavior, but that there will be some information that increases understanding with little or no impact on behavior. In addition, the features are likely to have varying impacts on understanding risks and consequences, motivation to take the safe course of action, and behavior. To test the generalizability of the guidelines, a large set of security dialogs from a wide range of software products will be collected. As candidate guidelines emerge, they will apply them to a variety of dialogs in their catalog and also observe which guidelines seem generally applicable and which seem to apply to only certain types of dialogs in our collection. Based on the final set of guidelines, the team will provide a number of example redesigns in a final project report and security dialog design tutorial that they will make publicly available.
这个项目的重点是提高计算机安全警告对话框的有效性?屏幕提示,警告用户潜在的安全风险,并让用户在两个或多个操作过程中进行选择。安全对话框应该帮助用户避免不安全的操作,同时通过提供信息,允许用户做出系统无法通过用户输入做出的明智决策,从而允许他们采取安全的操作。本研究采取了一种新的方法来设计和严格的评估计算机安全警告对话框,开发通用的指导方针,为软件产品设计有效的警告对话框的目标。这有可能帮助最终用户做出更好的安全决策,使他们的信息和计算机系统更安全,并改善计算机安全生态系统。的前期工作、文献回顾以及与合作者的讨论,他们开发了一组候选特性,这些特性将对安全对话的有效性产生重大影响。例如,这些功能包括:文本的数量和位置,语气的严重程度,如何帮助用户决定,描述风险和后果,使用推荐和默认选项等等。他们计划系统地研究应用于各种安全对话框的每个功能,以确定每个功能(单独或组合)的影响,并制定如何使用每个功能以达到最佳效果的指导方针。他们将遵循迭代设计和评估方法,涉及五种类型的研究:探索性访谈,土耳其机械研究,实验室研究,实地研究和界面设计师研究。在Mechanical Turk研究中,参与者将被提供一个场景和由该场景触发的安全对话框,并询问他们最有可能如何回应。他们还将被问到后续问题,以了解他们为什么做出这个决定,他们对每个警告对话框相关风险的看法,他们对警告对话框的理解,他们对自己理解警告对话框的程度的看法,以及他们对每个对话框中包含的概念和词汇的了解。我们将测量用户在风险场景中采取推荐操作和在良性场景中采取非推荐操作的趋势。后续问题将有助于确定用户行为的原因,以及如何最有效地设计安全警告对话框来影响这种行为。重要的是要确定如何就风险和后果进行有效沟通,还要确定用户在做出适当决定之前需要了解多少。预计情况的某些方面将与行为相关,但会有一些信息可以增加理解,而对行为影响很小或没有影响。此外,这些特征可能对理解风险和后果、采取安全行动的动机和行为产生不同的影响。为了测试准则的通用性,将从各种软件产品中收集大量安全对话框。随着候选准则的出现,他们将把它们应用到他们目录中的各种对话框中,并观察哪些准则似乎普遍适用,哪些准则似乎只适用于我们集合中的某些类型的对话框。根据最终的指导方针,该团队将在最终的项目报告和安全对话框设计教程中提供一些重新设计的示例,他们将公开提供。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Lorrie Cranor其他文献
Resist the Hype!
抵制炒作!
- DOI:
- 发表时间:
- 期刊:
- 影响因子:0
- 作者:
J. Fritzsch;Marvin Wyrich;J. Bogner;Stefan Wagner;Bob Blakley Bob Blakley;Lorrie Cranor - 通讯作者:
Lorrie Cranor
Lorrie Cranor的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Lorrie Cranor', 18)}}的其他基金
Conference: SaTC: NSF Secure & Trustworthy Cyberspace 2024 PI Meeting Logistics Management
会议:SaTC:NSF 安全
- 批准号:
2420955 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
协作提案:SaTC:前沿:分布式机密计算中心 (CDCC)
- 批准号:
2207216 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
Student Grants to Attend the Symposium On Usable Privacy and Security 2016 (SOUPS 16); June 22-24, 2016; Denver, Colorado
学生资助参加 2016 年可用隐私和安全研讨会 (SOUPS 16);
- 批准号:
1606543 - 财政年份:2016
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Student Travel Grants for Symposium On Usable Privacy and Security 2015
2015 年可用隐私和安全研讨会学生旅费资助
- 批准号:
1524070 - 财政年份:2015
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
TWC: Student travel grants for Symposium On Usable Privacy and Security 2014
TWC:2014 年可用隐私和安全研讨会的学生旅费补助金
- 批准号:
1441948 - 财政年份:2014
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Student travel grants for Symposium On Usable Privacy and Security 2013
2013 年实用隐私与安全研讨会学生旅费补助
- 批准号:
1254508 - 财政年份:2012
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Student Travel Grants for Symposium On Usable Privacy and Security 2012
2012 年可用隐私和安全研讨会学生旅费补助
- 批准号:
1243248 - 财政年份:2012
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
IGERT: Usable Privacy and Security
IGERT:可用的隐私和安全
- 批准号:
0903659 - 财政年份:2009
- 资助金额:
$ 50万 - 项目类别:
Continuing Grant
CT-ISG: Usable Cyber Trust Indicators
CT-ISG:可用的网络信任指标
- 批准号:
0831428 - 财政年份:2008
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
相似国自然基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
- 批准号:
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
- 批准号:n/a
- 批准年份:2022
- 资助金额:10.0 万元
- 项目类别:省市级项目
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
- 批准号:32000033
- 批准年份:2020
- 资助金额:24.0 万元
- 项目类别:青年科学基金项目
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
- 批准号:31972324
- 批准年份:2019
- 资助金额:58.0 万元
- 项目类别:面上项目
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
- 批准号:81900988
- 批准年份:2019
- 资助金额:21.0 万元
- 项目类别:青年科学基金项目
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
- 批准号:31802058
- 批准年份:2018
- 资助金额:26.0 万元
- 项目类别:青年科学基金项目
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
- 批准号:31870821
- 批准年份:2018
- 资助金额:56.0 万元
- 项目类别:面上项目
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
- 批准号:31772128
- 批准年份:2017
- 资助金额:60.0 万元
- 项目类别:面上项目
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
- 批准号:81704176
- 批准年份:2017
- 资助金额:20.0 万元
- 项目类别:青年科学基金项目
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
- 批准号:91640114
- 批准年份:2016
- 资助金额:85.0 万元
- 项目类别:重大研究计划
相似海外基金
Optimisation of small molecule inhibitors for effective targeting of phospholipase C gamma in T-cell lymphoma
优化小分子抑制剂以有效靶向 T 细胞淋巴瘤中的磷脂酶 C γ
- 批准号:
MR/Y503344/1 - 财政年份:2024
- 资助金额:
$ 50万 - 项目类别:
Research Grant
Designing safe, potent, and cost-effective small peptide erythropoietin analogs
设计安全、有效且经济有效的小肽促红细胞生成素类似物
- 批准号:
10602271 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
III: Small: A New Machine Learning Paradigm Towards Effective yet Efficient Foundation Graph Learning Models
III:小型:一种新的机器学习范式,实现有效且高效的基础图学习模型
- 批准号:
2321504 - 财政年份:2023
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SaTC: CORE: Small: Effective Design and Recommendation for Privacy-Preserving Data Visualizations
SaTC:核心:小型:隐私保护数据可视化的有效设计和建议
- 批准号:
2224066 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
CNS Core: Small: Software-Defined Video Analytics Pipeline: Enabling Resilient, High-Accuracy, and Resource-Effective Video Analytics
CNS 核心:小型:软件定义的视频分析管道:实现弹性、高精度和资源高效的视频分析
- 批准号:
2211459 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Cost-Effective Cyber Security for Small Businesses
为小型企业提供经济高效的网络安全
- 批准号:
10032395 - 财政年份:2022
- 资助金额:
$ 50万 - 项目类别:
Feasibility Studies
CNS Core: Small: Principled Methodologies and Systems Support for Automated Cost-Effective Service Blending in the Emerging Public Cloud
CNS 核心:小型:为新兴公共云中自动化、经济高效的服务混合提供原则性方法和系统支持
- 批准号:
2122155 - 财政年份:2021
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
SHF: SMALL: Effective and Equitable Technical Interviews in Software Engineering
SHF:小型:软件工程中有效且公平的技术面试
- 批准号:
2006977 - 财政年份:2020
- 资助金额:
$ 50万 - 项目类别:
Standard Grant
Development of slope disaster prevention technique by the small-diameter spiral pile for effective use of slopes
有效利用边坡的小直径螺旋桩边坡防灾技术开发
- 批准号:
20K04678 - 财政年份:2020
- 资助金额:
$ 50万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
CNS Core: Small: Test Framework for Easy and Effective Use of Network Verification
CNS Core:小型:轻松有效地使用网络验证的测试框架
- 批准号:
2007073 - 财政年份:2020
- 资助金额:
$ 50万 - 项目类别:
Standard Grant