首页> 外文OA文献 >Security Messages: Or, How I Learned to Stop Disregarding and Heed the Warning
【2h】

Security Messages: Or, How I Learned to Stop Disregarding and Heed the Warning

机译:安全消息:或者,我如何学会停止忽视和注意警告

摘要

Attacks on information security continue to be reported in the media, and result in large losses for organizations. While some attacks are the result of sophisticated threats, others can be traced to failures by organizational insiders to observe basic security policies such as using caution when opening unsolicited email attachments. Faced with the challenges and time demands of everyday stressors, security policy compliance can be costly for individuals; security actions require time and distract attention from other primary tasks. This costliness can lead individuals to ignore prompts to perform security updates, scan their computers for threats, or reboot their computers to apply security updates.ududThis dissertation contains three studies that address the following overarching research question: How can end-user adherence to security messages be better understood and improved, and how can theory inform security-message design? First, two complementary studies are presented that examine the integration of media naturalness theory into a security message context using field study and fMRI designs. Study 1, the field study, unobtrusively captures objective measures of attention from Amazon Mechanical Turk users (N=510) as they perform a between-subjects deception protocol. Study 2, the fMRI study, examines neural activations from a within-subjects participant design (N=23) in response to different security message designs with integrated emotive human facial expressions. Data from studies 1 and 2 show that warnings with integrated facial expressions of threat (fear, disgust) generally elicited greater adherence rates and higher evidence of cognition and elaboration than did warnings with integrated neutral facial expressions or than did warnings with no integrated facial expressions, supporting our hypotheses. Study 3 explores the pattern of risk taking and analysis that users engage in when interacting with interruptive security messages. The corroboration of multiple behavioral dependent variables suggests that users predominantly use a bimodal risk tradeoff paradigm when interacting with interruptive security messages. All three studies address the overarching research question of understanding and improving end user adherence to security messages.
机译:媒体上继续报道了对信息安全的攻击,给组织造成了巨大损失。尽管某些攻击是复杂威胁的结果,但组织内部人员可以将其他攻击归因于未能遵守基本安全策略,例如在打开未经请求的电子邮件附件时使用警告。面对日常压力源的挑战和时间要求,对个人而言,遵守安全策略可能会付出高昂的代价;安全行动需要时间,并会分散其他主要任务的注意力。这种昂贵的行为可能导致个人忽略执行安全更新的提示,扫描计算机的威胁或重新启动计算机以应用安全更新。 ud ud本论文包含三项研究,以解决以下总体研究问题:最终用户如何遵守如何更好地理解和改进安全消息?理论如何为安全消息设计提供信息?首先,提出了两项​​补充研究,这些研究使用现场研究和功能磁共振成像设计来检查将媒体自然性理论整合到安全消息上下文中的情况。实地研究研究1毫不费力地捕获了Amazon Mechanical Turk用户(N = 510)在执行对象间欺骗协议时的客观关注度。 fMRI研究的研究2研究了受试者内部参与者设计(N = 23)的神经激活,以响应具有集成化情感人脸表情的不同安全消息设计。研究1和2的数据表明,与带有中性面部表情的警告相比,与带有不完整面部表情的警告相比,带有威胁(恐惧,厌恶)的面部表情的警告通常会引起更高的依从率以及更高的认知和精致证据,支持我们的假设。研究3探索了用户与中断性安全消息进行交互时所承担的风险承担和分析模式。多个行为相关变量的证实表明,用户在与干扰性安全消息进行交互时主要使用双峰风险权衡范式。所有这三项研究都针对理解和提高最终用户对安全消息的遵守程度这一总体研究问题。

著录项

  • 作者

    Eargle David W.;

  • 作者单位
  • 年度 2017
  • 总页数
  • 原文格式 PDF
  • 正文语种 en
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号