Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
Detecting misalignments between system security and user perceptions: a preliminary socio-technical analysis of an E2E email encryption system
STOJKOVSKI, Borce; VAZQUEZ SANDOVAL, Itzel; LENZINI, Gabriele
2019In 4th European Workshop on Usable Security - 2019 IEEE European Symposium on Security and Privacy Workshops
Peer reviewed
 

Documents


Texte intégral
21.pdf
Postprint Auteur (1.12 MB)
Demander un accès

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
socio-technical security; UX; formal models
Résumé :
[en] The set of impressions that a user has about distinct aspects of a system depends on the experience perceived while interacting with the system. Considering the effects of these interactions in a security analysis allows for a new class of security properties in terms of misalignments between the system’s technical guarantees and the user’s impressions of them. For instance, a property that we call “false sense of insecurity” identifies a situation in which a secure system injects uncertainty in users, thus improperly transmitting the degree of protection that it actually provides; another, which we call “false sense of security”, captures situations in which a system instills a false sense of security beyond what a technical analysis would justify. Both situations leave room for attacks. In this paper we propose a model to define and reason about such socio-technical misalignments. The model refers to and builds on the concept of security ceremonies, but relies on user experience notions and on security analysis techniques to put together the information needed to verify misalignment properties about user’s impressions and system’s security guarantees. We discuss the innovative insight of this pilot model for a holistic understanding of a system’s security. We also propose a formal model that can be used with existing model checkers for an automatic analysis of misalignments. We exemplify the approach by modelling one specific application for end-to-end email encryption within which we analyze a few instances of misalignment properties.
Centre de recherche :
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > Applied Security and Information Assurance Group (APSIA)
Disciplines :
Sciences informatiques
Auteur, co-auteur :
STOJKOVSKI, Borce ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > Computer Science and Communications Research Unit (CSC)
VAZQUEZ SANDOVAL, Itzel ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
LENZINI, Gabriele ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT)
Co-auteurs externes :
no
Langue du document :
Anglais
Titre :
Detecting misalignments between system security and user perceptions: a preliminary socio-technical analysis of an E2E email encryption system
Date de publication/diffusion :
2019
Nom de la manifestation :
4th European Workshop on Usable Security
Lieu de la manifestation :
Stockholm, Suède
Date de la manifestation :
20-06-2019
Manifestation à portée :
International
Titre de l'ouvrage principal :
4th European Workshop on Usable Security - 2019 IEEE European Symposium on Security and Privacy Workshops
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Projet FnR :
FNR10621687 - Security And Privacy For System Protection, 2015 (01/01/2017-30/06/2023) - Sjouke Mauw
Intitulé du projet de recherche :
PRIDE15/10621687/SPsquared
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 24 juin 2019

Statistiques


Nombre de vues
353 (dont 56 Unilu)
Nombre de téléchargements
7 (dont 4 Unilu)

citations Scopus®
 
3
citations Scopus®
sans auto-citations
2

Bibliographie


Publications similaires



Contacter ORBilu