论文标题

什么违反?通过研究现实世界浏览行为来衡量在线对安全事件的认识

What breach? Measuring online awareness of security incidents by studying real-world browsing behavior

论文作者

Bhagavatula, Sruti, Bauer, Lujo, Kapadia, Apu

论文摘要

对安全和隐私风险的认识对于培养良好的安全习惯很重要。了解现实世界中的安全事件和数据泄露,可以提醒人们在网上易受伤害的信息,从而在鼓励安全的安全行为中发挥重要作用。本文研究1)人们多久在网上阅读有关安全事件的频率,2)这些人,无论他们在何种程度上跟进了一项行动,例如试图阅读有关事件的更多信息,以及3)影响他们阅读事件并采取一些行动的可能性。我们通过定量检查303名参与者的现实世界浏览数据来研究这一点。 我们的发现表现出对安全事件意识的黯淡看法。只有16%的参与者访问了与六起广泛宣传的大规模安全事件有关的任何网页;即使事件可能影响了它们,也很少有人读过一篇关于它们的信息(例如,Equifax违反了几乎普遍影响的Equifax信用报告)。我们进一步发现,更严重的事件以及对事件进行建设性谈论的文章启发了更多的行动。我们最终提出了针对未来研究的建议,并促使有用的安全事件信息可以吸引更多人。

Awareness about security and privacy risks is important for developing good security habits. Learning about real-world security incidents and data breaches can alert people to the ways in which their information is vulnerable online, thus playing a significant role in encouraging safe security behavior. This paper examines 1) how often people read about security incidents online, 2) of those people, whether and to what extent they follow up with an action, e.g., by trying to read more about the incident, and 3) what influences the likelihood that they will read about an incident and take some action. We study this by quantitatively examining real-world internet-browsing data from 303 participants. Our findings present a bleak view of awareness of security incidents. Only 16% of participants visited any web pages related to six widely publicized large-scale security incidents; few read about one even when an incident was likely to have affected them (e.g., the Equifax breach almost universally affected people with Equifax credit reports). We further found that more severe incidents as well as articles that constructively spoke about the incident inspired more action. We conclude with recommendations for specific future research and for enabling useful security incident information to reach more people.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源