Evaluating the Information Security Awareness of Smartphone Users

要旨

Information security awareness (ISA) is a practice focused on the set of skills which help a user successfully mitigate social engineering (SE) attacks. Evaluating the ISA of users is crucial, since early identification of users who are more vulnerable to SE attacks improves system security. Previous studies for evaluating the ISA of smartphone users rely on subjective data sources (questionnaires) and do not address the differences between classes of SE attacks. This paper presents a framework for evaluating the ISA of smartphone users for specific attack classes. In addition to questionnaires, we utilize objective data sources: a mobile agent, a network traffic monitor, and cybersecurity challenges. We evaluated the framework by conducting a long-term user study involving 162 users. The results show that: the self-reported behavior of users differs significantly from their actual behavior and the ISA level derived from the actual behavior of users is highly correlated with their ability to mitigate SE attacks.

受賞
Honorable Mention
キーワード
Information Security Awareness
Social Engineering
Human Factors
Mobile Devices
著者
Ron Bitton
Ben Gurion University, Be'er Sheba, Israel
Kobi Boymgold
Ben Gurion University, Be'er Sheba, Israel
Rami Puzis
Ben Gurion University, Be'er Sheba, Israel
Asaf Shabtai
Ben Gurion University, Be'er Sheba, Israel
DOI

10.1145/3313831.3376385

論文URL

https://doi.org/10.1145/3313831.3376385

会議: CHI 2020

The ACM CHI Conference on Human Factors in Computing Systems (https://chi2020.acm.org/)

セッション: Security awareness, training & practices

Paper session
313B O'AHU
5 件の発表
2020-04-29 18:00:00
2020-04-29 19:15:00
日本語まとめ
読み込み中…