首页> 外文会议>IEEE World Congress on Services >Expressing Security Requirements: Usability of Taxonomy-Based Requirement Identification Scheme
【24h】

Expressing Security Requirements: Usability of Taxonomy-Based Requirement Identification Scheme

机译:表达安全要求:基于分类的需求识别方案的可用性

获取原文

摘要

Users want to enjoy online services without sacrificing their security. Although there is a trade-off between the security of a service and its usability, the level of security required will differ depending on the user and the situation. To optimize the balance between security and usability, it can be customized for each user and each online transaction. Yet in order to do that, both users and service providers need to stipulate their security requirements. We have been working on a framework that provides security requirement classifications in multiple dimensions to help users identify and select their security requirements, and then apply these requirements to different dimensions. This paper shows how we implemented this framework and then evaluated it by conducting a user study along with our implementation. The study verifies that ordinary users without any particular technical knowledge prefer to clarify their security requirements using a taxonomy-based selection scheme (our scheme) as opposed to a free-form input scheme. It also discusses the coverage of pre-defined taxonomies and users' requirements. Through this study, we clarify the future direction of our research.
机译:用户希望在不牺牲安全性的情况下享受在线服务。虽然服务的安全性和可用性之间存在权衡,但需要的安全水平取决于用户和情况。为了优化安全性和可用性之间的平衡,可以为每个用户和每个在线事务进行自定义。然而,为了做到这一点,用户和服务提供商都需要规定他们的安全要求。我们一直在研究一个框架,提供多维的安全要求分类,以帮助用户识别并选择其安全要求,然后将这些要求应用于不同的维度。本文展示了我们如何实现本框架,然后通过我们的实施方式进行用户学习来评估它。该研究验证了没有任何特定技术知识的普通用户更喜欢使用基于分类的选择方案(我们的计划)而不是自由形式输入方案来澄清其安全要求。它还讨论了预定分类的分类和用户要求的覆盖范围。通过这项研究,我们澄清了我们研究的未来方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号