Mental Models of Computer Security Risks

نویسندگان

  • Farzaneh Asgharpour
  • Debin Liu
  • L. Jean Camp
چکیده

Improved computer security requires improvements in risk communication to naive end users. Efficacy of risk communication depends not only on the nature of the risk, but also on the alignment between the conceptual model embedded in the risk communication and the recipients’ perception of the risk. The difference between these communicated and perceived mental models could lead to ineffective risk communication. The experiment described in this paper shows that for a variety of security risks self-identified security experts and non-experts have different mental models. We illustrate that this outcome is sensitive to the definition of “expertise”. We also show that the models implicit in the literature do not correspond to experts or non-expert mental models. We propose that risk communication should be designed based on the non-expert’s mental models with regard to each security risk and discuss how this can be done.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Experimental Evaluations of Expert and Non-expert Computer Users’ Mental Models of Security Risks

1 2 There is a critical need in computer security to communicate risks and thereby enable informed decisions by naive users. Yet computer security has not been engaged with the scholarship of risk communication. While the existence of malicious actors may appear at first to distinguish computer risk from environmental or medical risk, the impersonal un-targeted nature of the exploitation of com...

متن کامل

Risk Communication in Security Using Mental Models

In computer security, risk communication refers to a mechanism used to inform computer users against a given threat. Efficacy of risk communication depends not only on the nature of the risk, but also alignment between the conceptual model of the risk communicator and the user’s perception or mental model of the risk. The gap between the mental model of the security experts and non-experts coul...

متن کامل

POSTER: What is still wrong with security warnings: a mental models approach

Warnings are a form of communication specifically designed to protect people from harm [9]. There is evidence that people do not read computer warnings [4] [8], do not understand them [3], or simply do not heed them [7], even when the situation is clearly hazardous. Most of this evidence comes from studying users’ responses to potential phishing threats, and a variety of explanations have been ...

متن کامل

"My Data Just Goes Everywhere: " User Mental Models of the Internet and Implications for Privacy and Security

Many people use the Internet every day yet know little about how it really works. Prior literature diverges on how people’s Internet knowledge affects their privacy and security decisions. We undertook a qualitative study to understand what people do and do not know about the Internet and how that knowledge affects their responses to privacy and security risks. Lay people, as compared to those ...

متن کامل

Effectively Communicate Risks for Diverse Users: A Mental-Models Approach for Individualized Security Interventions

Security interventions – such as Web warnings – currently do not work. One approach to remedy the situation is to make the communication of risks in the interventions more understandable and motivating. Mental models that users have of security have been studied to accomplish these aims, primarily to better align the intervention with the mental model of the users. However, the users’ mental mo...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2007