...
首页> 外文期刊>ACM Transaction on Information and System Security >Technological and Human Factors of Malware Attacks: A Computer Security Clinical Trial Approach
【24h】

Technological and Human Factors of Malware Attacks: A Computer Security Clinical Trial Approach

机译:恶意软件攻击的技术和人为因素:一种计算机安全性临床试验方法

获取原文
获取原文并翻译 | 示例
           

摘要

The success (or failure) of malware attacks depends upon both technological and human factors. The most security-conscious users are susceptible to unknown vulnerabilities, and even the best security mechanisms can be circumvented as a result of user actions. Although there has been significant research on the technical aspects of malware attacks and defence, there has been much less research on how users interact with both malware and current malware defences.This article describes a field study designed to examine the interactions between users, antivirus (AV) software, and malware as they occur on deployed systems. In a fashion similar to medical studies that evaluate the efficacy of a particular treatment, our experiment aimed to assess the performance of AV software and the human risk factors of malware attacks. The 4-month study involved 50 home users who agreed to use laptops that were instrumented to monitor for possible malware attacks and gather data on user behaviour. This study provided some very interesting, non-intuitive insights into the efficacy of AV software and human risk factors. AV performance was found to be lower under real-life conditions compared to tests conducted in controlled conditions. Moreover, computer expertise, volume of network usage, and peer-to-peer activity were found to be significant correlates of malware attacks. We assert that this work shows the viability and the merits of evaluating security products, techniques, and strategies to protect systems through long-term field studies with greater ecological validity than can be achieved through other means.
机译:恶意软件攻击的成功(或失败)取决于技术和人为因素。最注重安全性的用户容易受到未知漏洞的影响,甚至最好的安全性机制也可能由于用户操作而被规避。尽管对恶意软件攻击和防御的技术方面已有大量研究,但有关用户如何与恶意软件和当前恶意软件防御进行交互的研究却很少。本文介绍了一项旨在检查用户之间的交互的实地研究,即防病毒( AV)软件和恶意软件(它们在已部署的系统上发生)。以类似于评估特定治疗功效的医学研究的方式,我们的实验旨在评估AV软件的性能以及恶意软件攻击的人类危险因素。这项为期4个月的研究涉及50位家庭用户,他们同意使用笔记本电脑,这些笔记本电脑可以监视可能的恶意软件攻击并收集有关用户行为的数据。这项研究提供了一些非常有趣的,非直觉性的见解,以了解AV软件的功效和人类危险因素。与在受控条件下进行的测试相比,在现实生活条件下的AV性能要低。此外,发现计算机专业知识,网络使用量以及对等活动是恶意软件攻击的重要关联。我们断言,这项工作通过对生态有效性的长期野外研究,显示了评估安全产品,技术和策略来保护系统的可行性和优点,而这种有效性远高于通过其他手段所无法实现的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号