论文标题

网络上有效的通知活动:信任,框架和支持问题

Effective Notification Campaigns on the Web: A Matter of Trust, Framing, and Support

论文作者

Maass, Max, Stöver, Alina, Pridöhl, Henning, Bretthauer, Sebastian, Herrmann, Dominik, Hollick, Matthias, Spiecker, Indra

论文摘要

配置错误和过时的软件是损害网站和数据泄漏的主要原因。过去的研究已提出并评估了将自动安全通知发送给错误配置的网站的运营商,但遇到了具有可及性,不信任和认为缺乏重要性的问题。在本文中,我们试图了解有效通知的决定因素。我们确定了数据保护错误配置,影响了我们扫描的130万个网站中的12.7%,并使他们承担法律责任。使用4754个网站的子集,我们进行了一个多元随机对照通知实验,评估触点介质,发件人和消息的框架。我们还包括一个基于公共网络的自助工具的链接,该工具由我们伪装并对通知网站所有者(n = 477)进行匿名调查,以了解其观点。 我们发现,将错误的配置作为法律合规性问题可以提高补救率,尤其是当该通知作为法律研究小组的信件发送,达到76.3%的补救率,而计算机科学研究人员发送的电子邮件则为33.9%,警告有关隐私问题的电子邮件。在所有组中,有56.6%的通知所有者对此问题进行了补救,而对照组为9.2%。总而言之,我们提出了导致网站所有者信任通知的因素,显示通知的框架将它们置于行动,以及如何在纠正问题时得到支持。

Misconfigurations and outdated software are a major cause of compromised websites and data leaks. Past research has proposed and evaluated sending automated security notifications to the operators of misconfigured websites, but encountered issues with reachability, mistrust, and a perceived lack of importance. In this paper, we seek to understand the determinants of effective notifications. We identify a data protection misconfiguration that affects 12.7 % of the 1.3 million websites we scanned and opens them up to legal liability. Using a subset of 4754 websites, we conduct a multivariate randomized controlled notification experiment, evaluating contact medium, sender, and framing of the message. We also include a link to a public web-based self-service tool that is run by us in disguise and conduct an anonymous survey of the notified website owners (N=477) to understand their perspective. We find that framing a misconfiguration as a problem of legal compliance can increase remediation rates, especially when the notification is sent as a letter from a legal research group, achieving remediation rates of 76.3 % compared to 33.9 % for emails sent by computer science researchers warning about a privacy issue. Across all groups, 56.6 % of notified owners remediated the issue, compared to 9.2 % in the control group. In conclusion, we present factors that lead website owners to trust a notification, show what framing of the notification brings them into action, and how they can be supported in remediating the issue.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源