课题基金 / 基金详情

TC: Small: Effective Security Warning Dialogs

TC: Small: Effective Security Warning Dialogs
TC:小:有效的安全警告对话框
批准号:
1116934
负责人:
Lorrie Cranor
金额:
$50.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2011
资助国家:
美国
项目状态:
已结题
起止时间:
2011-09-01 至 2015-08-31

项目摘要

项目成果

Lorrie Cranor的其他基金

相似基金

相关文献

中文摘要
翻译
这个项目的重点是提高计算机安全警告对话框的有效性。屏幕提示,警告用户潜在的安全风险,并让用户在两个或多个操作方案之间进行选择。安全对话框应该帮助用户避免不安全的操作,同时通过显示允许用户做出系统无法通过用户输入做出的明智决策的信息来允许他们采取安全的操作。本研究采用了一种新颖的方法来设计和严格评估计算机安全警告对话框,目的是为软件产品设计有效的警告对话框提供可推广的指导方针。这有可能帮助最终用户做出更好的安全决策,使他们的信息和计算机系统更安全,并改善计算机安全生态系统。基于卡内基梅隆大学的团队?通过先前的工作、文献回顾以及与合作者的讨论,他们开发了一组候选特性,这些特性将对安全对话的有效性产生重大影响。例如,这些功能包括:文本的数量和位置、语气的严重性、如何帮助用户做出决定、描述风险和后果、推荐和默认选项的使用等等。他们计划系统地研究每个特性,应用于各种安全对话,以确定每个特性(单独或组合)的影响,并制定如何使用每个特性以达到最佳效果的指导方针。他们将遵循迭代设计和评估方法,包括五种类型的研究:探索性访谈、土耳其机械研究、实验室研究、实地研究和界面设计师研究。在机械土耳其人的研究中,参与者将被提供一个场景和由该场景触发的安全对话,并被问及他们最有可能如何回应。他们还将被问及后续问题,以了解他们为什么做出这个决定,他们对每个警告对话相关风险的看法,他们对警告对话的理解,他们认为自己理解警告对话的程度,以及他们对每个对话中包含的概念和词汇的了解程度。我们将衡量用户在风险场景中采取推荐操作的倾向,以及在良性场景中采取不推荐操作的倾向。后续的问题将帮助确定为什么用户会有这样的行为,以及如何最有效地设计安全警告对话框来影响这种行为。确定如何有效地就风险和后果进行沟通非常重要,但也要确定用户在做出适当的决定之前需要了解多少内容。预计情况的某些方面将与行为相关,但会有一些信息增加理解,对行为影响很小或没有影响。此外,这些特征可能会对风险和后果的理解、采取安全行动的动机和行为产生不同的影响。为了测试指南的通用性,将收集来自各种软件产品的大量安全性对话框。随着候选指南的出现,他们将把它们应用到他们目录中的各种对话框中,并观察哪些指南似乎是普遍适用的,哪些似乎只适用于我们集合中的某些类型的对话框。根据最终的指导方针集,团队将在最终的项目报告和安全对话框设计教程中提供许多重新设计的示例,并将向公众提供。
英文摘要
This project focuses on improving the effectiveness of computer security warning dialogs ? on-screen prompts that warn users about a potential security risks and give users a choice between two or more courses of action. Security dialogs should help users avoid unsafe actions while allowing them to take safe actions by presenting information that allows users to make informed decisions that the system cannot make with user input. This research takes a novel approach to the design and rigorous evaluation of computer security warning dialogs, with the goal of developing generalizable guidelines for designing effective warning dialogs for software products. This has the potential to help end users make better security decisions that keep their information and computer systems safer, and improve the computer security ecosystem.Based on the Carnegie-Mellon team?s previous work, review of the literature, and discussions with collaborators, they have developed a set of candidate features that will have a significant impact on the effectiveness of security dialogs. For example, these features include: amount and placemen of text, severity of tone, how to help users decide, describing risks and consequences, use of recommended and default options, and more. They plan to systematically study each feature, applied to a variety of security dialogs, to determine the impact of each (individually and in combination) and to develop guidelines on how to use each feature to best effect. They will follow an iterative design and evaluation approach that will involve five types of studies: exploratory interviews, Mechanical Turk studies, laboratory studies, field studies, and interface designer studies. In the Mechanical Turk studies, participants will be provided with a scenario and a security dialog triggered by that scenario and asked how they would be most likely to respond. They will also be asked follow-up questions to learn why they made that decision, their perception of the risks associated with each warning dialog, their understanding of the warning dialog, their beliefs about how well they think they understand the warning dialog, and their knowledge of the concepts and vocabulary included in each dialog. We will measure the tendency for users to take the recommended action in risky scenarios and the non-recommended action in benign scenarios. The follow-up questions will help determine why users behave the way they do and how to most effectively design security warning dialogs to influence that behavior. It is important to determine how to communicate effectively about the risks and consequences, but also to determine how much users need to be able to understand before they make appropriate decisions. It is anticipated that of some aspects of the situation will be correlated with behavior, but that there will be some information that increases understanding with little or no impact on behavior. In addition, the features are likely to have varying impacts on understanding risks and consequences, motivation to take the safe course of action, and behavior. To test the generalizability of the guidelines, a large set of security dialogs from a wide range of software products will be collected. As candidate guidelines emerge, they will apply them to a variety of dialogs in their catalog and also observe which guidelines seem generally applicable and which seem to apply to only certain types of dialogs in our collection. Based on the final set of guidelines, the team will provide a number of example redesigns in a final project report and security dialog design tutorial that they will make publicly available.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Conference: SaTC: NSF Secure & Trustworthy Cyberspace 2024 PI Meeting Logistics Management
  • 批准号:
    2420955
  • 项目类别:
    Standard Grant
  • 资助金额:
    $69.68万
  • 财政年份:
    2024
  • 负责人:
    Lorrie Cranor
  • 依托单位:
Collaborative Proposal: SaTC: Frontiers: Center for Distributed Confidential Computing (CDCC)
  • 批准号:
    2207216
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $88.0万
  • 财政年份:
    2022
  • 负责人:
    Lorrie Cranor
  • 依托单位:
Student Grants to Attend the Symposium On Usable Privacy and Security 2016 (SOUPS 16); June 22-24, 2016; Denver, Colorado
  • 批准号:
    1606543
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2016
  • 负责人:
    Lorrie Cranor
  • 依托单位:
Student Travel Grants for Symposium On Usable Privacy and Security 2015
  • 批准号:
    1524070
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.5万
  • 财政年份:
    2015
  • 负责人:
    Lorrie Cranor
  • 依托单位:
国内基金
海外基金
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
  • 依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
  • 批准号:
  • 项目类别:
    省市级项目
  • 资助金额:
    10.0万元
  • 批准年份:
    2022
  • 负责人:
    张祥忠
  • 依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
  • 批准号:
    31972324
  • 项目类别:
    面上项目
  • 资助金额:
    58.0万元
  • 批准年份:
    2019
  • 负责人:
    高学文
  • 依托单位: