User compliance and remediation success after IoT malware notifications

被引:5
|
作者
Rodriguez, Elsa [1 ]
Verstegen, Susanne [1 ]
Noroozian, Arman [1 ]
Inoue, Daisuke [2 ]
Kasama, Takahiro [2 ]
van Eeten, Michel [1 ]
Ganan, Carlos H. [1 ]
机构
[1] Delft Univ Technol, Org & Governance, Jaffalaan 5, NL-2628 BX Delft, Netherlands
[2] Natl Inst Informat & Commun Technol, 4-2-1 Nukui Kitamachi, Koganei, Tokyo 1848195, Japan
来源
JOURNAL OF CYBERSECURITY | 2021年 / 7卷 / 01期
基金
荷兰研究理事会;
关键词
IoT security; cleanup IoT malware; user compliance on IoT notifications; REGRESSION; DDOS;
D O I
10.1093/cybsec/tyab015
中图分类号
C [社会科学总论];
学科分类号
03 ; 0303 ;
摘要
Internet Service Providers (ISPs) are getting involved in remediating Internet of Things (IoT) infections of end users. This endeavor runs into serious usability problems. Given that it is usually unknown what kind of device is infected, they can only provide users with very generic cleanup advice, trying to cover all device types and remediation paths. Does this advice work? To what extent do users comply with the instructions? And does more compliance lead to higher cleanup rates? This study is the first to shed light on these questions. In partnership with an ISP, we designed a randomized control experiment followed up by a user survey. We randomly assigned 177 consumers affected by malware from the Mirai family to three different groups: (i) notified via a walled garden (quarantine network), (ii) notified via email, and (iii) no immediate notification, i.e. a control group. The notification asks the user to take five steps to remediate the infection. We conducted a phone survey with 95 of these customers based on communication-human information processing theory. We model the impact of the treatment, comprehension, and motivation on the compliance rate of each customer, while controlling for differences in demographics and infected device types. We also estimate the extent to which compliance leads to successful cleanup of the infected IoT devices. While only 24% of notified users perform all five remediation steps, 92% of notified users perform at least one action. Compliance increases the probability of successful cleanup by 32%, while the presence of competing malware reduces it by 54%. We provide an empirical basis to shape ISP best practices in the fight against IoT malware.
引用
收藏
页数:21
相关论文
共 8 条
  • [1] Critical Success Factors to Improve Compliance with Campus Emergency Notifications
    Han, Wencui
    Ada, Serkan
    Sharman, Raj
    Raghav, Rao H.
    Brennan, Joseph
    [J]. AMCIS 2011 PROCEEDINGS, 2011,
  • [2] NURSE: eNd-UseR IoT malware detection tool for Smart homEs
    d'Estalenx, Antoine
    Ganan, Carlos H.
    [J]. 11TH INTERNATIONAL CONFERENCE ON THE INTERNET OF THINGS, IOT 2021, 2021, : 134 - 142
  • [3] Distributed Query Results and IoT Data in a Publish-Subscribe Network Implementing User Notifications
    Sanchez de Rivera, Diego
    Alcarria, Ramon
    Martin, Diego
    Sanchez-Picot, Alvaro
    Bordel, Borja
    Robles, Tomas
    [J]. IEEE 30TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS WORKSHOPS (WAINA 2016), 2016, : 778 - 783
  • [4] Difficult for Thee, But Not for Me: Measuring the Difficulty and User Experience of Remediating Persistent IoT Malware
    Rodriguez, Elsa
    Fukkink, Max
    Parkin, Simon
    van Eeten, Michel
    Ganan, Carlos
    [J]. 2022 IEEE 7TH EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY (EUROS&P 2022), 2022, : 392 - 409
  • [5] MDHE: A Malware Detection System Based on Trust Hybrid User-Edge Evaluation in IoT Network
    Deng, Xiaoheng
    Tang, Haowen
    Pei, Xinjun
    Li, Deng
    Xue, Kaiping
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 5950 - 5963
  • [6] Life after ERP implementation Long-term development of user perceptions of system success in an after-sales environment
    Hakkinen, Lotta
    Hilmola, Olli-Pekka
    [J]. JOURNAL OF ENTERPRISE INFORMATION MANAGEMENT, 2008, 21 (03) : 285 - +
  • [7] Outcomes of an enhanced recovery after radical cystectomy program in a prospective multicenter study: compliance and key components for success
    Llorente, C.
    Guijarro, A.
    Hernandez, V
    Fernandez-Conejo, G.
    Passas, J.
    Aguilar, L.
    Tejido, A.
    Hernandez, C.
    Moralejo, M.
    Subira, D.
    Gonzalez-Enguita, C.
    Husillos, A.
    Ortiz, F.
    Sanchez-Chapado, M.
    Carballido, J.
    Castillon, I
    Mateo, E.
    Romero, I
    Fernandez del Alamo, J.
    Llanes, L.
    Blazquez, C.
    Sanchez-Encinas, M.
    Borrego, J.
    Tellez, M.
    Diez, L.
    Carrero, V. M.
    Perez-Fernandez, E.
    Fuentes-Ramirez, L.
    Garcia Del Valle, S.
    [J]. WORLD JOURNAL OF UROLOGY, 2020, 38 (12) : 3121 - 3129
  • [8] Outcomes of an enhanced recovery after radical cystectomy program in a prospective multicenter study: compliance and key components for success
    C. Llorente
    A. Guijarro
    V. Hernández
    G. Fernández-Conejo
    J. Passas
    L. Aguilar
    A. Tejido
    C. Hernández
    M. Moralejo
    D. Subirá
    C. González-Enguita
    A. Husillos
    F. Ortiz
    M. Sánchez-Chapado
    J. Carballido
    I. Castillón
    E. Mateo
    I. Romero
    J. Fernández del Álamo
    L. Llanes
    C. Blázquez
    M. Sánchez-Encinas
    J. Borrego
    M. Téllez
    L. Díez
    V. M. Carrero
    E. Pérez-Fernández
    L. Fuentes-Ramirez
    S. García Del Valle
    [J]. World Journal of Urology, 2020, 38 : 3121 - 3129