Alerting about possible risks vs. blocking risky choices: A quantitative model and its empirical evaluation

被引:1
|
作者
Meyer, Joachim [1 ]
Dembinsky, Omer [1 ]
Raviv, Tal [1 ]
机构
[1] Tel Aviv Univ, Dept Ind Engn, Tel Aviv, Israel
关键词
Cyber security; Alerts; Alarms; Warnings; Blocking; Signal detection theory; Decision making; Optimal behavior modeling; Behavioral validation; AUTOMATION FALSE ALARMS; BIAS; RELIANCE; COMPLACENCY; BEHAVIOR; SYSTEMS; DESIGN; TRUST;
D O I
10.1016/j.cose.2020.101944
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Alerting users about possible threats or blocking users' ability to perform potentially dangerous actions are two common ways to protect systems from the adverse effects of threats, such as malicious email attachments, fraudulent requests, or system malfunctions. We present a normative model of the effects of alerting and blocking on the value of the outcomes, on measures of risk-taking, and on the number of successful attacks. We compared warning and blocking systems and binaryand likelihood-alarm systems as a function of properties of the threats and the security system. We also compared model predictions to actual user behavior, as measured in a controlled experiment. The experimental results were generally in line with the normative model. However, the model predicted that the outcomes from blocking would always be worse or equal to those from warnings. The experiment, however, showed that blocking may have an advantage over warnings, because it leads to fewer undetected events (as predicted by the model), without significantly lowering the mean value of outcomes (the model predicts a lower value). We discuss practical implications regarding the use of blocking and alerting and the more general value of combining optimal decision models and empirical experiments for determining system designs. (c) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:13
相关论文
共 2 条
  • [1] Automata Language Equivalence vs. Simulations for Model-based Mutant Equivalence: An Empirical Evaluation
    Devroey, Xavier
    Perrouin, Gilles
    Papadakis, Mike
    Legay, Axel
    Schobbens, Pierre-Yves
    Heymans, Patrick
    [J]. 2017 10TH IEEE INTERNATIONAL CONFERENCE ON SOFTWARE TESTING, VERIFICATION AND VALIDATION (ICST), 2017, : 424 - 429
  • [2] LAST OBSERVATION CARRIED FORWARD (LOCF) VS. MIXED-EFFECTS MODEL REPEATED MEASURES (MMRM): EMPIRICAL EVALUATION OF TWO APPROACHES TO ANALYZING LONGITUDINAL DATA WITH MISSING OBSERVATIONS
    Jo, H.
    Gemmen, E.
    Bharmal, M.
    [J]. VALUE IN HEALTH, 2010, 13 (07) : A333 - A333