Experimental Evaluations of Expert and Non-expert Computer Users’ Mental Models of Security Risks

نویسندگان

  • Jean Camp
  • Farzaneh Asgharpour
  • Debin Liu
چکیده

1 2 There is a critical need in computer security to communicate risks and thereby enable informed decisions by naive users. Yet computer security has not been engaged with the scholarship of risk communication. While the existence of malicious actors may appear at first to distinguish computer risk from environmental or medical risk, the impersonal un-targeted nature of the exploitation of computing resources and the technical complexity of the risks are similarities. This work is a first experimental step in evaluating the informal, implicit, and unexamined use of mental models in computer security. The experiments described in this paper have three results. First, the experiments show that for a wide range of security risks self-identified security experts and non-experts have quite distinct mental models. Second, a stronger definition of expertise increases the distance between the mental models of non-experts and experts. Finally, the implicit and informal use of models through metaphors in the computer security community has not resulted in metaphors that match the mental models of naive users, and more surprisingly , of self-identified experts. We close with a description of our research agenda targeted at developing a better understanding of the mental models of naive users. Reference as Farzeneh Asgapour, Debin Liu and L. Jean Camp, Risk Communication in Computer Security using Mental Models, WEIS 2007, (Pittsburgh, PA) 5-6 June 2007. This work was produced in part with support from the Institute for Information Infrastructure Protection research program. The I3P is managed by Dartmouth College, and supported under Award number 2003-TK-TX-0003 from the U.S. DHS, Science and Technology Directorate. This material is based upon work supported by the National Science Foundation under award number 0705676. Opinions, findings, conclusions, recommendations or points of view in this document are those of the author(s) and do not necessarily represent the official position of the U.S. Department of Homeland Security, National Science Foundation, the Science and Technology Directorate, the I3P, the NSF, Indiana University, or Dartmouth College.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Mental Models of Computer Security Risks

Improved computer security requires improvements in risk communication to naive end users. Efficacy of risk communication depends not only on the nature of the risk, but also on the alignment between the conceptual model embedded in the risk communication and the recipients’ perception of the risk. The difference between these communicated and perceived mental models could lead to ineffective r...

متن کامل

Effectively Communicate Risks for Diverse Users: A Mental-Models Approach for Individualized Security Interventions

Security interventions – such as Web warnings – currently do not work. One approach to remedy the situation is to make the communication of risks in the interventions more understandable and motivating. Mental models that users have of security have been studied to accomplish these aims, primarily to better align the intervention with the mental model of the users. However, the users’ mental mo...

متن کامل

Designing an Expert System for Internet Connection Problems Troubleshooting for wired network users

Man, is living in an era that the knowledge is estimated to be doubled in a relatively short time. The fast rate of technology's growth in the "Century of information", is caused by fast growth of communication technologies like the internet which has become one of the best tools for a quick, cheap, effective and vastly supported communication. For an efficient and effective usage of tools and ...

متن کامل

Designing an Expert System for Internet Connection Problems Troubleshooting for wired network users

Man, is living in an era that the knowledge is estimated to be doubled in a relatively short time. The fast rate of technology's growth in the "Century of information", is caused by fast growth of communication technologies like the internet which has become one of the best tools for a quick, cheap, effective and vastly supported communication. For an efficient and effective usage of tools and ...

متن کامل

Risk Communication in Security Using Mental Models

In computer security, risk communication refers to a mechanism used to inform computer users against a given threat. Efficacy of risk communication depends not only on the nature of the risk, but also alignment between the conceptual model of the risk communicator and the user’s perception or mental model of the risk. The gap between the mental model of the security experts and non-experts coul...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2008