首页> 外文会议>IEEE Symposium on Security and Privacy >'Should I Worry?' A Cross-Cultural Examination of Account Security Incident Response
【24h】

'Should I Worry?' A Cross-Cultural Examination of Account Security Incident Response

机译:“我应该担心吗?”帐户安全事件响应的跨文化检查

获取原文

摘要

Digital security technology is able to identify and prevent many threats to users accounts. However, some threats remain that, to provide reliable security, require human intervention: e.g., through users paying attention to warning messages or completing secondary authentication procedures. While prior work has broadly explored people's mental models of digital security threats, we know little about users' precise, in-the-moment response process to in-the-wild threats. In this work, we conduct a series of qualitative interviews (n=67) with users who had recently experienced suspicious login incidents on their real Facebook accounts in order to explore this process of account security incident response. We find a common process across participants from five countries - with differing online and offline cultures - allowing us to identify areas for future technical development to best support user security. We provide additional insights on the unique nature of incident-response information seeking, known attacker threat models, and lessons learned from a large, cross-cultural qualitative study of digital security.
机译:数字安全技术能够识别并防止对用户帐户的许多威胁。但是,为了提供可靠的安全性,仍然存在一些需要人为干预的威胁:例如,通过用户注意警告消息或完成辅助身份验证过程。尽管先前的工作广泛地探索了人们对数字安全威胁的心理模型,但我们对用户对野生威胁的精确,即时响应过程知之甚少。在这项工作中,我们对最近在其真实Facebook帐户上遇到可疑登录事件的用户进行了一系列定性访谈(n = 67),以探索此帐户安全事件响应过程。我们发现来自五个国家/地区的参与者具有共同的流程-在线和离线文化不同-使我们能够确定未来技术开发的领域,以最佳地支持用户安全。我们提供有关事件响应信息查找,已知攻击者威胁模型以及从大型跨文化定性数字安全性研究中汲取的教训的独特性质的其他见解。

著录项

获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号