How Users Bypass Access Control and Why : The Impact of Authorization Problems on Individuals and the Organization 24 / 05 / 2012

نویسندگان

  • Steffen Bartsch
  • M. Angela Sasse
چکیده

Many organizations struggle with ineffective and/or inefficient access control, but these problems and their consequences often remain invisible to security decision-makers. Prior research has focused on improving the policy-authoring part of authorization and does not show the full range of problems, their impact on organizations, and underlying causes. We present a study of 118 individual's experiences of authorization measures in a multi-national company and their self-reported subsequent behavior. We follow the recent advances in applying economic models to security usability and analyze the interrelations of authorization issues with individuals' behaviors and organizational goals. Our results indicate that authorization problems significantly impact the productivity and effective security of organizations. From the data, we derive authorization Personas and their daily problems, which are to a large extent caused by the procedures for policy changes and the decision-making, and lead to the circumvention of the measure. As one research contribution, we develop a holistic model of authorization problems. More practically, we recommend to monitor non-compliance, such as password-sharing, for indications of authorization problems, and to establish light-weight procedures for policy changes with adequate degrees of centralization and formalization, and support for decision-making. UCL DEPARTMENT OF COMPUTER SCIENCE How Users Bypass Access Control and Why Bartsch and Sasse

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

How Users Bypass Access Control - And Why: The Impact Of Authorization Problems On Individuals And The Organization

Many organizations struggle with ineffective and/or inefficient access control, but these problems and their consequences often remain invisible to security decision-makers. Prior research has focused on improving the policy-authoring part of authorization and does not consider the full range of underlying problems, and their impact on organizations. We present a study of 118 individuals’ exper...

متن کامل

Authorization models for secure information sharing: a survey and research agenda

This article presents a survey of authorization models and considers their 'fitness-for-purpose' in facilitating information sharing. Network-supported information sharing is an important technical capability that underpins collaboration in support of dynamic and unpredictable activities such as emergency response, national security, infrastructure protection, supply chain integration and emerg...

متن کامل

Access control in ultra-large-scale systems using a data-centric middleware

  The primary characteristic of an Ultra-Large-Scale (ULS) system is ultra-large size on any related dimension. A ULS system is generally considered as a system-of-systems with heterogeneous nodes and autonomous domains. As the size of a system-of-systems grows, and interoperability demand between sub-systems is increased, achieving more scalable and dynamic access control system becomes an im...

متن کامل

A combination of semantic and attribute-based access control model for virtual organizations

A Virtual Organization (VO) consists of some real organizations with common interests, which aims to provide inter organizational associations to reach some common goals by sharing their resources with each other. Providing security mechanisms, and especially a suitable access control mechanism, which enforces the defined security policy is a necessary requirement in VOs. Since VO is a complex ...

متن کامل

Role Based Access Mechanism in Cloud Computing: Survey

Cloud Computing provides the people the way to share distributed resources and services that belongs to different organization or sites. In cloud computing at present there is no authorization recycling approach. The aim of the paper is to study an authorization recycling approach using with role-based access control, access decisions are based on the roles that individual users have as part of...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2012