Skip to main content
QUICK REVIEW

[论文解读] Human Factors in Security Research: Lessons Learned from 2008-2018

Mannat Kaur, Michel van Eeten|arXiv (Cornell University)|Mar 24, 2021
Information and Cyber Security参考文献 142被引用 10
一句话总结

本文分析了2008年至2018年十年间网络安全领域的人因研究,聚焦于系统管理员和开发人员等专家用户,并将其研究与终端用户研究进行对比。研究识别出若干关键缺陷,如以西方为中心的偏见、理论基础薄弱以及伦理实践不一致,并建议通过整合安全科学原则、多样化样本、加强理论应用以及规范化伦理实践,以提升该领域的科学严谨性与现实相关性。

ABSTRACT

Instead of only considering technology, computer security research now strives to also take into account the human factor by studying regular users and, to a lesser extent, experts like operators and developers of systems. We focus our analysis on the research on the crucial population of experts, whose human errors can impact many systems at once, and compare it to research on regular users. To understand how far we advanced in the area of human factors, how the field can further mature, and to provide a point of reference for researchers new to this field, we analyzed the past decade of human factors research in security and privacy, identifying 557 relevant publications. Of these, we found 48 publications focused on expert users and analyzed all in depth. For additional insights, we compare them to a stratified sample of 48 end-user studies. In this paper we investigate: (i) The perspective on human factors, and how we can learn from safety science (ii) How and who are the participants recruited, and how this -- as we find -- creates a western-centric perspective (iii) Research objectives, and how to align these with the chosen research methods (iv) How theories can be used to increase rigor in the communities scientific work, including limitations to the use of Grounded Theory, which is often incompletely applied (v) How researchers handle ethical implications, and what we can do to account for them more consistently Although our literature review has limitations, new insights were revealed and avenues for further research identified.

研究动机与目标

  • 评估当前关于计算机安全领域专家用户的人因研究现状,尤其聚焦于系统开发人员、操作员和管理员。
  • 将专家导向的研究与终端用户研究进行对比,以识别方法论和概念上的异同。
  • 识别研究设计中的系统性问题,如抽样偏差、理论框架薄弱以及伦理实践不一致。
  • 通过借鉴安全科学和社会心理学等成熟学科,提出改进建议,以增强研究的科学严谨性与可推广性。
  • 通过具体建议引导未来研究,包括理论整合、方法多样化以及伦理标准统一。

提出的方法

  • 对2008年至2018年间关于信息安全与隐私的人因研究的557篇文献进行了系统性文献回顾,并对其中48项专家导向研究进行了深入分析。
  • 将这48项专家研究与48项终端用户研究的分层样本进行对比,以对照研究目标、方法和理论参与度。
  • 采用主题分析法,识别研究视角、参与者招募方式、研究目标、方法选择、理论应用以及伦理考量中的模式。
  • 评估定性研究中对基础理论(Grounded Theory)的应用,识别出常见误用,如数据收集不完整以及理论饱和度不足。
  • 运用安全科学的理论框架(如偏差正常化、错误的系统性)批判安全领域中“最弱环节”模型的人因错误观。
  • 提出由社区驱动的伦理委员会,并应用文化维度理论,提出改善样本多样性和外部效度的策略。

实验结果

研究问题

  • RQ1安全科学中的哪些见解可应用于改善对计算机安全中人因因素的理解,特别是对错误系统性成因的理解?
  • RQ2当前研究中专家用户的招募方式如何?该过程在多大程度上导致了以西方为中心的偏见?
  • RQ3专家导向的人因研究的主要研究目标是什么?这些目标与所选研究方法的契合度如何?
  • RQ4理论框架在专家导向的人因研究中应用的一致性与有效性如何?当前理论应用存在哪些局限?
  • RQ5人因研究中对专家的研究伦理问题如何处理?有哪些机制可提升各研究间伦理实践的一致性?

主要发现

  • 绝大多数专家导向的人因研究参与者来自美国和欧洲,导致显著的西方中心主义偏见,限制了研究发现的可推广性。
  • 仅少数研究明确使用理论框架;当使用时,往往应用不完整,许多研究声称使用基础理论,但未遵循其完整的方法论流程。
  • “最弱环节”模型(将安全失败归咎于个体)仍占主导地位,尽管安全科学证据表明错误是系统性且具有概率性的,而非个体失误。
  • 研究目标多为探索性或描述性,对基于用户行为设计或评估安全系统的关注有限,表明在应用性、理论指导的设计研究方面存在明显缺口。
  • 伦理考量处理不一致,许多研究缺乏正式的伦理审查,尤其在非学术或产业主导的研究中更为明显,凸显了建立标准化伦理监督机制的迫切需求。
  • 复制研究极为罕见,研究发现很少在不同社会经济或文化背景下进行验证,严重削弱了该领域的外部效度与累积性进展。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。