首页> 外文会议>IEEE World Congress on Services >Expressing Security Requirements: Usability of Taxonomy-Based Requirement Identification Scheme
【24h】

Expressing Security Requirements: Usability of Taxonomy-Based Requirement Identification Scheme

机译:表达安全需求:基于分类的需求识别方案的可用性

获取原文

摘要

Users want to enjoy online services without sacrificing their security. Although there is a trade-off between the security of a service and its usability, the level of security required will differ depending on the user and the situation. To optimize the balance between security and usability, it can be customized for each user and each online transaction. Yet in order to do that, both users and service providers need to stipulate their security requirements. We have been working on a framework that provides security requirement classifications in multiple dimensions to help users identify and select their security requirements, and then apply these requirements to different dimensions. This paper shows how we implemented this framework and then evaluated it by conducting a user study along with our implementation. The study verifies that ordinary users without any particular technical knowledge prefer to clarify their security requirements using a taxonomy-based selection scheme (our scheme) as opposed to a free-form input scheme. It also discusses the coverage of pre-defined taxonomies and users' requirements. Through this study, we clarify the future direction of our research.
机译:用户希望在不牺牲安全性的情况下享受在线服务。尽管在服务的安全性及其可用性之间需要权衡取舍,但所需的安全性级别将取决于用户和情况而有所不同。为了优化安全性和可用性之间的平衡,可以针对每个用户和每个在线交易对其进行自定义。然而,为了做到这一点,用户和服务提供商都需要规定他们的安全要求。我们一直在研究一个框架,该框架提供了多个维度的安全需求分类,以帮助用户识别和选择他们的安全需求,然后将这些需求应用于不同的维度。本文展示了我们如何实现此框架,然后通过进行用户研究以及我们的实现对其进行评估。该研究证实,没有任何特殊技术知识的普通用户更喜欢使用基于分类法的选择方案(我们的方案)来阐明他们的安全要求,而不是使用自由格式的输入方案。它还讨论了预定义分类法的范围和用户的要求。通过这项研究,我们阐明了我们研究的未来方向。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号