학술논문

Formal Mental Models for Human-Centered Cybersecurity.
Document Type
Article
Source
International Journal of Human-Computer Interaction. Mar2024, p1-17. 17p. 12 Illustrations, 2 Charts.
Subject
Language
ISSN
1044-7318
Abstract
AbstractHuman users are increasingly recognized as a vector of cybersecurity attack. One problem that contributes to this condition is the growing complexity of digital tools. Such complexity can make it difficult for users to understand how tools work and how their actions will impact security. This work sought to answer the research question: Can mental modeling analyses (from human factors engineering and human-automation interaction) be developed to effectively discover cybersecurity risks? To answer this, we extend mental models with cybersecurity-specific concepts. The resulting models are then incorporated into model checking analyses (an automated approach to formal verification) to discover if and when mismatches between human mental models and systems can cause security failures. We evaluated our approach by successfully applying it to a case study regarding the security configuration of a popular cloud data storage service. We ultimately discuss the results of this analysis and outline future research possibilities. [ABSTRACT FROM AUTHOR]