首页> 外文会议>Seventh International Conference on Risks and Security of Internet and Systems. >Don't work. Can't work? Why it's time to rethink security warnings
【24h】

Don't work. Can't work? Why it's time to rethink security warnings

机译:不要工作不行吗为什么是时候重新考虑安全警告了

获取原文
获取原文并翻译 | 示例

摘要

As the number of Internet users has grown, so have the security threats that they face online. Security warnings are one key strategy for trying to warn users about those threats; but recently, it has been questioned whether they are effective. We conducted a study in which 120 participants brought their own laptops to a usability test of a new academic article summary tool. They encountered a PDF download warning for one of the papers. All participants noticed the warning, but 98 (81.7%) downloaded the PDF file that triggered it. There was no significant difference between responses to a brief generic warning, and a longer specific one. The participants who heeded the warning were overwhelmingly female, and either had previous experience with viruses or lower levels of computing skills. Our analysis of the reasons for ignoring warnings shows that participants have become desensitised by frequent exposure and false alarms, and think they can recognise security risks. At the same time, their answers revealed some misunderstandings about security threats: for instance, they rely on anti-virus software to protect them from a wide range of threats, and do not believe that PDF files can infect their machine with viruses. We conclude that security warnings in their current forms are largely ineffective, and will remain so, unless the number of false positives can be reduced.
机译:随着Internet用户数量的增长,他们在线面临的安全威胁也越来越大。安全警告是试图警告用户这些威胁的一种关键策略。但是最近,有人质疑它们是否有效。我们进行了一项研究,其中120名参与者将他们自己的笔记本电脑带到了新的学术文章摘要工具的可用性测试中。他们遇到其中一篇论文的PDF下载警告。所有参与者都注意到了该警告,但98(81.7%)个下载了触发该警告的PDF文件。对简短的一般警告和较长的特定警告的响应之间没有显着差异。遵守警告的参与者绝大多数是女性,并且曾经有过病毒方面的经验或较低的计算技能。我们对忽略警告的原因的分析表明,参与者已因频繁暴露和错误警报而变得不敏感,并认为他们可以识别安全风险。同时,他们的回答揭示了对安全威胁的一些误解:例如,他们依靠防病毒软件来保护自己免受各种威胁的侵害,并且他们不相信PDF文件会感染病毒。我们得出的结论是,除非可以减少误报的数量,否则当前形式的安全警告将一直无效,并且将一直如此。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号