Tradeoffs Between Usability and Security in Information Assurance
This presentation discusses the tradeoffs between usability and security in information assurance, emphasizing the importance of continuously patching machines, avoiding phishing websites, using strong passwords, and more. It also explores the concept of usable security and the ecological validity of study methods in password memorability research.
Download Presentation
Please find below an Image/Link to download the presentation.
The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.
You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.
The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.
E N D
Presentation Transcript
Content may be borrowed from other resources. See the last slide for acknowledgements! Usable Security Amir Houmansadr CS660: Advanced Information Assurance Spring 2015
Tradeoffs Between Usability and Security Continuously patch your machine, or get compromised Beware of phishing websites Frequently run CPU/memory-intensive antiviruses Deploy stringent firewall software Use different passwords for different websites, do not write them down, pick strong passwords (hard to remember) Do not store sensitive information on mobile devices prone to be lost/stolen CS660 - Advanced Information Assurance - UMassAmherst 2
Usable Security Definition: Security measures developed with attention to usability considerations (Or, to make security measures usable!) A sub-area of security Less technical, but significantly important CS660 - Advanced Information Assurance - UMassAmherst 3
Secure, but usable? CS660 - Advanced Information Assurance - UMassAmherst 4
How Does Your Password Measure Up? The Effect of Strength Meters on Password Creation Click to see slides from the authors CS660 - Advanced Information Assurance - UMassAmherst 5
Ecological Validity The methods, materials, and setting of the study must approximate the real-world being examined Does the memorability results have ecological validity? Participants likely did not care to remember passwords Should experiment with real users as opposed to paid users CS660 - Advanced Information Assurance - UMassAmherst 6
Acknowledgement Some of the slides, content, or pictures are borrowed from the following resources, and some pictures are obtained through Google search without being referenced below: CS660 - Advanced Information Assurance - UMassAmherst 7