Evaluating security tools towards usable security
نویسندگان
چکیده
The main success of the internet is its openness. To guarantee security in the internet for example to protect the user’s privacy or the security of online transactions the use of security tools is essential. Because today’s internet users cover almost all educational levels and professional groups, we assume that they will be mostly security novices. Unfortunately, the usage of today’s security tools is mostly too complex and incomprehensible, thus opening security leaks caused by incorrect usage. In order to identify security leaks arising from the user interface, an objective measure for the usability of security tools is necessary. At present, such a measure does not exist. This paper develops such a measure for the usability of security tools. We propose problem categories for errors in security tools. Based on this categorization, we propose a taxonomy for the usability of security functions. Applying this taxonomy, security functions may be ranked according to the user’s ability to avoid self-induced, security-critical user errors. Additionally, the taxonomy may explain possible causes of errors, introducing design alternatives to avoid these errors.
منابع مشابه
A framework for usable and secure system design
Despite existing work on dealing with security and usability concerns during the early stages of design, there has been little work on synthesising the contributions of these fields into processes for specifying and designing systems. Without a better understanding of how to deal with both concerns at an early stage, the design process risks disenfranchising stakeholders, and resulting systems ...
متن کاملA Framework for Evaluating Usable Security: The Case of Online Health Social Networks
It is vital that the development of security and privacy features for applications and websites are assessed for their usability. An assessment of such usability will increase the continuous and effective utilisation from the user perspective. However, owing to a lack of tools and methods this is difficult to achieve. There is thus a need for a usable security framework to facilitate the usabil...
متن کاملTowards a Usable-Security Engineering Framework for Enhancing Software Development
Title: Towards a Usable-Security Engineering Framework for Enhancing Software Development Author: Yasser M. Hausawi Committee Chair: William H. Allen, Ph.D. Computer systems are fundamental tools for almost every single process in life. People from all over the globe use computer systems for an unlimited number of purposes. Consequently, a close relationship between people and computer systems ...
متن کاملChallenges in Universally Usable Privacy and Security
Accessibility concerns compound the already-considerable difficulties of building systems that provide usable privacy and security. In addition to facing common concerns regarding the semantics of privacy and security tools, people with disabilities face accessibility obstacles, such as the inaccessibility of CAPTCHAs, phishing toolbars, verification images, and other displays that rely upon vi...
متن کاملTowards Tool-Support for Usable Secure Requirements Engineering with CAIRIS
Understanding how to better elicit, specify, and manage requirements for secure and usable software systems is a key challenge in security software engineering, however, there lacks tool-support for specifying and managing the voluminous amounts of data the associated analysis yields. Without these tools, the subjectivity of analysis may increase as design activities progress. This paper descri...
متن کامل