Human-centered computer security
Jim Blythe · Journal of computing sciences in colleges · 2014
Research in computer security has produce and array of tools that are essential to safe computing, including access control, firewalls and anti-virus systems. However attackers still gain access to protected networks regularly, partly because researchers have ignored the people who fill the networks and operate those tools. We are not always rational, may have a poor mental model of security and tend to see the tools as onerous, hindering us in our work, difficult to understand and oblivious to how our organization functions. What can be done about this? Fieldwork can help us gain a better understanding of how people interact with security systems, somtimes defeating tools intended to protect them. Our experimental user interface learns the user's mental model of security and uses the knowledge to communicate risk and choices more effectively. Cognitive architectures can model human decisions about security, to better imulate the impact of security systems in a testbed like DETER. I will describe some existing undergraduate and grad courses in human-centered security. The topic provides a great context for integrating different areas of computer science, including computer security, user interfaces, cognitive science and artificial intelligence.