ACM Home Page
Please provide us with feedback. Feedback
Aligning usability and security: a usability study of Polaris
Full text PdfPdf (269 KB)
Source ACM International Conference Proceeding Series; Vol. 149 archive
Proceedings of the second symposium on Usable privacy and security table of contents
Pittsburgh, Pennsylvania
SESSION: Intelligible access control table of contents
Pages: 1 - 7  
Year of Publication: 2006
ISBN:1-59593-448-0
Authors
Alexander J. DeWitt  Brunel University, West London, UK
Jasna Kuljis  Brunel University, West London, UK
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 13,   Downloads (12 Months): 123,   Citation Count: 1
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Review this Article  
Save this Article to a Binder    Display Formats: BibTex  EndNote ACM Ref   
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1143120.1143122
What is a DOI?

ABSTRACT

Security software is often difficult to use thus leading to poor adoption and degraded security. This paper describes a usability study that was conducted on the software 'Polaris'. This software is an alpha release that uses the Principle of Least Authority (POLA) to deny viruses the authority to edit files. Polaris was designed to align security with usability. The study showed that despite this aim, usability problems remained, especially when the study participants had to make security related decisions. They also showed apathy towards security, and knowingly compromised their security to get work done faster. This study also demonstrates the difficulty in achieving security and usability alignment when the usability is a post hoc consideration added to a developed product, rather than being integrated from the start. The alleviation of usability problems from security software proposed in this paper are threefold: reducing the burden on the user to make security related decisions, counteracting user's apathy by ensuring that the fast way of doing things is the secure way, and integrating security software with the operating system throughout development.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
 
2
 
3
Brooke, J., Sus: A quick and dirty usability scale, in Usability evaluation in industry, P. Jordan, B. Thomas, and B. Weerdmeester, Editors. 1996, Taylor and Francis: London.
4
 
5
Dourish, P., J. Delgado de la Flor, and M. Joseph. Security as a practical problem: Some preliminary observations of everyday mental models. in Workshop on HCI and Security Systems, CHI20032003. Fort Lauderdale, Florida, USA: ACM.
6
 
7
eBay, Using ebay toolbar's account guard, http://pages.ebay.com/help/confidence/account-guard.html. 2006. Accessed on 20th April 2006.
8
9
 
10
Gerd, D. and T. Markotten. User-centered security engineering. in Nordu20022002. Helsinki, Finland.
 
11
Gutmann, P., Inadvertent case study in ssl server cert effectiveness, hcisec@Yahoogroups.com, Editor. 2005.
 
12
ISO, Ergonomic requirements for office work with visual display terminals (vdts) - part 11: Guidance on usability. 1998, BSI.
 
13
Nielsen, J., Security & human factors, http://www.useit.com/alertbox/20001126.html. 2000. Accessed on 20th February 2006.
 
14
Nielsen, J., Why you only need to test with 5 users, http://www.useit.com/alertbox/20000319.html. 2000. Accessed on 29th November 2005.
15
 
16
Saltzer, J. and M. Schroeder, The protection of information in computer systems. Proceedings of the IEEE, 1975. 63(9): p. 1278--1308.
 
17
Stiegler, M., A. H. Karp, K.-P. Yee, and M. Miller, Polaris: Virus safe computing for windows xp. 2004, HP. http://www.hpl.hp.com/techreports/2004/HPL-2004-221.html
 
18
Straub, T. and H. Baier. A framework for evaluating the usability and the utility of pki-enabled applications. in EuroPKI. 112--125 2004. Samos Island, Greece: Springer-Verlag GmbH.
 
19
20
 
21
Whitten, A. and J. D. Tygar. Why johnny can't encrypt: A usability evaluation of pgp 5.0. in Proceedings of the 8th USENIX security symposium. 169--184 1999. Washington, D.C.
 
22
 
23
 
24
 
25
26


Collaborative Colleagues:
Alexander J. DeWitt: colleagues
Jasna Kuljis: colleagues