Improving the Usability of Web Browser Security

نویسندگان

  • Haidong Xia
  • José Carlos Brustoloni
چکیده

Existing Web browsers handle security errors in a manner that often confuses users. In particular, when a user visits a secure site whose certificate the browser cannot verify, the browser typically allows the user to view and install the certificate and connect to the site despite the verification failure. However, few users understand the risk of man-in-the-middle attacks and the principles behind certificate-based authentication. We propose context-sensitive certificate verification (CSCV), whereby the browser interrogates the user about the context in which a certificate verification error occurs. Considering the context, the browser then guides the user in handling and possibly overcoming the security error. We also propose specific password warnings (SPW) when users are about to send passwords in a form vulnerable to eavesdropping. We performed user studies to evaluate CSCV and SPW. Our results suggest that CSCV and SPW can greatly improve Web browsing security and are easy to use even without training. Moreover, CSCV had greater impact than did staged security training.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Improving internet banking security by using differentiated authentication based on risk profiling

Online security remains a challenge to ensure safe transacting on the internet. User authentication, a human-centric process, is regarded as the basis of computer security and hence secure access to online banking services. The increased use of technology to enforce additional actions has the ability to improve the quality of authentication and hence online security, but often at the expense of...

متن کامل

A Browser-Based Approach to Smart Card Connectivity

Smart cards have provided security services for a wide range of applications including telecommunication, banking, and citizen identification. Connecting web applications with smart cards is a natural step forward to address some of the security issues in today’s Web. The traditional approach for smart card based web applications provides security, but has the drawbacks of usability and flexibi...

متن کامل

Integrating of Web browsers and applications with strong authentication

With the growing popularity of the Internet, the Web browser is emerging as perhaps the most widely used type of user interface. Many desktop applications made use of a Web browser as a key component in their overall system design. The most common approach to integrate a Web browser into an application system is to open a Web browser as an external process with a URL. Alternatively, some Web br...

متن کامل

A Systematic Review on Measuring and Evaluating Web Usability in Model Driven Web Development

1 Department of Information Technology, SreeVidyanikethan Engineering College,Tirupati, India 2 Assistant Professor, SreeVidyanikethan Engineering College, Tirupati, India 1 [email protected], 2 [email protected] ________________________________________________________________________________________________________ Abstract—The unquestionable relevance of the web in our society has...

متن کامل

Position Paper: Improving Browsing Environment Compliance Evaluations for Websites

Though it would be ideal for web pages to render and function consistently across heterogeneous browsing environments, the browser, browser version, and operating system used to navigate and interact with web content is known to have a significant impact on the subsequent level of user accessibility. While research endeavors directed toward improving web accessibility have generally focused on ...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005