首页> 美国卫生研究院文献>other >Susceptibility and resilience to cyber threat: Findings from a scenario decision program to measure secure and insecure computing behavior
【2h】

Susceptibility and resilience to cyber threat: Findings from a scenario decision program to measure secure and insecure computing behavior

机译:对网络威胁的易感性和恢复力:来自方案决策程序的结果用于测量安全和不安全的计算行为

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Interest in the individual differences underlying end user computer security behavior has led to the development of a multidisciplinary field of research known as behavioral information security. An important gap in knowledge and the motivation for this research is the development of ways to measure secure and insecure cyber behavior for research and eventually practice. Here we report a study designed to develop a technique for assessing secure and insecure cyber behavior for broad research use. The Susceptibility and Resilience to Cyber Threat (SRCT) is an immersive scenario decision program. The SRCT measures susceptibility to cyber threat and malicious behavior as well protective resilience actions via participant responses/decisions to emails, interactions with security dialogs, and computer actions in a real-world simulation. Data were collected from a sample of 190 adults (76.3% female), between the ages of 18–61 (mean age = 26.12). Personality, behavioral tendencies, and cognitive preferences were measured with standard previously validated protocols and self-report measures. Factor analysis suggested a 5 item secure actions scale and a 9 item insecure actions scale as viable to extract from the SRCT responses. Statistically analyzable distributions of secure and insecure cyber behaviors were obtained, and these subscales demonstrated acceptable internal consistency as hypothesized. Associations between SRCT scales and other indices of cyber behavior, as well as self-reported personality, were lower than predicted, suggesting that past research reporting links between self-reports of personality and self-reported cyber-behavior may be overestimating the links for actual cyber actions. However, our exploratory analyses suggest discrepancies between self-report and actions in the SRCT may be an interesting avenue to explore. Overall, results were consistent with theorizing and suggest the technique is viable as a construct measure in future research or as an outcome variable in experimental intervention designs.
机译:对最终用户计算机安全行为所基于的个体差异的兴趣导致了多学科研究领域的发展,这被称为行为信息安全。这项研究的知识和动机上的一个重要缺口是,开发了用于研究和最终实践的测量安全和不安全网络行为的方法。在这里,我们报告了一项旨在开发一种技术的评估研究,该技术可用于广泛研究中评估安全和不安全的网络行为。网络威胁的易感性和恢复力(SRCT)是一种沉浸式场景决策程序。 SRCT通过参与者对电子邮件的响应/决策,与安全对话框的交互以及真实世界模拟中的计算机操作,来衡量对网络威胁和恶意行为的敏感性以及保护性恢复措施。数据来自18至61岁(平均年龄= 26.12)之间的190名成年人(女性占76.3%)的样本。人格,行为倾向和认知偏好通过标准的先前验证过的方案和自我报告测评来衡量。因子分析表明,可以从SRCT响应中提取5个项目的安全行为量表和9个项目的不安全行为量表。获得了安全和不安全的网络行为的统计分析分布,并且这些量表证明了假设的可接受的内部一致性。 SRCT量表与其他网络行为指标以及自我报告的人格之间的关联性低于预期,这表明以往研究报告中关于自我自我报告与自我报告的网络行为之间的联系可能高估了实际联系。网络行动。但是,我们的探索性分析表明,自我报告和SRCT中的行为之间的差异可能是一个有趣的探索途径。总体而言,结果与理论一致,表明该技术可作为未来研究中的构建指标或作为实验干预设计中的结果变量。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号