Back to Search Start Over

Formal Mental Models for Human-Centered Cybersecurity.

Authors :
Houser, Adam M.
Bolton, Matthew L.
Source :
International Journal of Human-Computer Interaction. Mar2024, p1-17. 17p. 12 Illustrations, 2 Charts.
Publication Year :
2024

Abstract

AbstractHuman users are increasingly recognized as a vector of cybersecurity attack. One problem that contributes to this condition is the growing complexity of digital tools. Such complexity can make it difficult for users to understand how tools work and how their actions will impact security. This work sought to answer the research question: Can mental modeling analyses (from human factors engineering and human-automation interaction) be developed to effectively discover cybersecurity risks? To answer this, we extend mental models with cybersecurity-specific concepts. The resulting models are then incorporated into model checking analyses (an automated approach to formal verification) to discover if and when mismatches between human mental models and systems can cause security failures. We evaluated our approach by successfully applying it to a case study regarding the security configuration of a popular cloud data storage service. We ultimately discuss the results of this analysis and outline future research possibilities. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
10447318
Database :
Academic Search Index
Journal :
International Journal of Human-Computer Interaction
Publication Type :
Academic Journal
Accession number :
175876483
Full Text :
https://doi.org/10.1080/10447318.2024.2314353