Do Different Mental Models Influence Cybersecurity Behavior? Evaluations via Statistical Reasoning Performance
نویسندگان
چکیده
Cybersecurity research often describes people as understanding internet security in terms of metaphorical mental models (e.g., disease risk, physical security risk, or criminal behavior risk). However, little research has directly evaluated if this is an accurate or productive framework. To assess this question, two experiments asked participants to respond to a statistical reasoning task framed in one of four different contexts (cybersecurity, plus the above alternative models). Each context was also presented using either percentages or natural frequencies, and these tasks were followed by a behavioral likelihood rating. As in previous research, consistent use of natural frequencies promoted correct Bayesian reasoning. There was little indication, however, that any of the alternative mental models generated consistently better understanding or reasoning over the actual cybersecurity context. There was some evidence that different models had some effects on patterns of responses, including the behavioral likelihood ratings, but these effects were small, as compared to the effect of the numerical format manipulation. This points to a need to improve the content of actual internet security warnings, rather than working to change the models users have of warnings.
منابع مشابه
Towards a Human Factors Ontology for Cyber Security
Traditional cybersecurity risk assessment is reactive and based on business risk assessment approach. The 2014 NIST Cybersecurity Framework provides businesses with an organizational tool to catalog cybersecurity efforts and areas that need additional support. As part of an on-going effort to develop a holistic, predictive cyber security risk assessment model, the characterization of human fact...
متن کاملA Computational Account of Social Reasoning
People are amateur social psychologists: they explain other people’s behavior, infer what other people are thinking and feeling, and predict how other people will act. I will refer to this sort of psychologizing as social reasoning in order to highlight the fact that it involves reasoning about people. Social reasoning often requires significant leaps of inductive inference: people infer others...
متن کاملPerception of Risk and Terrorism-Related Behavior Change: Dual Influences of Probabilistic Reasoning and Reality Testing
The present study assessed the degree to which probabilistic reasoning performance and thinking style influenced perception of risk and self-reported levels of terrorism-related behavior change. A sample of 263 respondents, recruited via convenience sampling, completed a series of measures comprising probabilistic reasoning tasks (perception of randomness, base rate, probability, and conjunctio...
متن کاملDark Knowledge in Qualitative Reasoning: A Call to Arms
While people do qualitative reasoning, there is ample evidence that they do not always do it well. Two current crises, human-induced climate change and the financial meltdown, can be traced in part to faulty mental models. The QR community has formalisms that can potentially help with public education about such problems, but so far we have not been very successful in doing so. We claim that pa...
متن کاملConstraint Satisfaction Processes in Social Reasoning
We show that constraint satisfaction processes (coherence based reasoning) play an important role in social reasoning, and that social reasoning violates key assumptions of classic models of judgment and decision-making. Constraint satisfaction models predict a bi-directional flow of influence between evaluations of evidence for a judgment and the judgment itself, such that an evolving judgment...
متن کامل