论文标题
认证建议的成本和收益
Costs and benefits of authentication advice
论文作者
论文摘要
提供身份验证安全建议的目的是指导用户和组织采取安全的行动和实践。在本文中,我们证明安全建议可能是模棱两可的,矛盾的,有时甚至可能没有明显的好处。我们通过定义确定安全建议成本的正式方法并启动用户研究以确定适用于各种身份验证建议的成本来扩展当前工作。我们还采用一个简单的框架来分析建议与建议相关的安全益处。这使我们能够确定所有类别的安全建议的成本和收益。
Authentication security advice is given with the goal of guiding users and organisations towards secure actions and practices. In this paper, we demonstrate that security advice can be ambiguous, contradictory and at times may not even have any clear benefits. We expand on current work by defining a formal approach to identifying costs of security advice and instigate a user study to identify the costs that apply to a large range of authentication advice. We also apply a simple framework for analysing the authentication related security benefits of advice. This allows us to identify costs and benefits for all classes of security advice.