2019•Unpublished venueRequires access

Towards Better Security Decisions

Leilei Qu, Cheng Wang, Ruojin Xiao, Jianwei Hou, Wenchang Shi, Bin Liang

Open publisher page 10 citations

Abstract

Normal users are usually not good at making decisions about cybersecurity, being easily attacked by hackers. Quite a few tools have been devised and implemented to help, but they can not balance security and usability well. To solve the problem, this paper explores the application of prospect theory to security recommendations. We conducted online surveys (n=61) and a between-subjects experiment (n=106) in six conditions to investigate the issues. In the experiment, we provided different security recommendations about two-factor-authentication (2FA) to participants in different conditions and recorded their decisions about enabling it. Results show that participants in the condition "Disadvantage" were willing to adopt 2FA the most. The findings indicate that showing disadvantages can be useful to persuade users into better security decisions.

About this research paper

What this paper is about

Normal users are usually not good at making decisions about cybersecurity, being easily attacked by hackers. Quite a few tools have been devised and implemented to help, but they can not balance security and usability well. To solve the problem, this paper explores the application of prospect theory to security recommendations. We conducted online surveys (n=61) and a between-subjects experiment (n=106) in six conditions to investigate the issues. In the experiment, we provided different security recommendations about two-factor-authentication (2FA) to participants in different conditions and recorded their decisions about enabling it. Results show that participants in the condition "Disadvantage" were willing to adopt 2FA the most. The findings indicate that showing disadvantages can be useful to persuade users into better security decisions.

Why it matters

OpenAlex reports 10 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Normal users are usually not good at making decisions about cybersecurity, being easily attacked by hackers. Quite a few tools have been devised and implemented to help, but they can not balance security and usability well. To solve the problem, this paper explores the application of prospect theory to security recommendations. We conducted online surveys (n=61) and a between-subjects experiment (n=106) in six conditions to investigate the issues. In the experiment, we provided different security recommendations about two-factor-authentication (2FA) to participants in different conditions and recorded their decisions about enabling it. Results show that participants in the condition "Disadvantage" were willing to adopt 2FA the most. The findings indicate that showing disadvantages can be useful to persuade users into better security decisions.

Key concepts: Hacker, Usability, Disadvantage, Computer science, Computer security, Authentication (law), Human-computer interaction in information security, Internet privacy

Related papers

Back to paper searchBrowse research topicsOriginal source
Towards Better Security Decisions — Research Paper | ScholarLens