| Seeing further: extending visualization as a basis for usable security |
| Full text |
Pdf
(352 KB)
|
| Source
|
ACM International Conference Proceeding Series; Vol. 149
archive
Proceedings of the second symposium on Usable privacy and security
table of contents
Pittsburgh, Pennsylvania
SESSION: Risk transparency
table of contents
Pages: 145 - 155
Year of Publication: 2006
ISBN:1-59593-448-0
|
|
Authors
|
|
Jennifer Rode
|
University of California, Irvine, Irvine, CA
|
|
Carolina Johansson
|
Uppsala University, Uppsala, Sweden
|
|
Paul DiGioia
|
University of California, Irvine, Irvine, CA
|
|
Roberto Silva Filho
|
University of California, Irvine, Irvine, CA
|
|
Kari Nies
|
University of California, Irvine, Irvine, CA
|
|
David H. Nguyen
|
University of California, Irvine, Irvine, CA
|
|
Jie Ren
|
University of California, Irvine, Irvine, CA
|
|
Paul Dourish
|
University of California, Irvine, Irvine, CA
|
|
David Redmiles
|
University of California, Irvine, Irvine, CA
|
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 13, Downloads (12 Months): 89, Citation Count: 1
|
|
|
ABSTRACT
The focus of our approach to the usability considerations of privacy and security has been on providing people with information they can use to understand the implications of their interactions with a system, as well as, to assess whether or not a system is secure enough for their immediate needs. To this end, we have been exploring two design principles for secure interaction: visualizing system activity and integrating configuration and action. Here we discuss the results of a user study designed as a broad formative examination of the successes and failures of an initial prototype based around these principles. Our response to the results of this study has been twofold. First, we have fixed a number of implementation and usability problems. Second, we have extended our visualizations to incorporate new considerations regarding the temporal and structural organization of interactions.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
| |
1
|
Jetty Java HTTP Servlet Server, Mort Bay Consulting <http://jetty.mortbay.org/jetty/>.
|
| |
2
|
The Jakarta Slide Projects, <http://jakarta.apache.org/slide/>
|
| |
3
|
Altman, I. (1975). The Environment and Social Behavior. Privacy Personal Space, Territory and Crowding. Monterey, CA. Brooks/Cole Pub. Co., Inc.
|
| |
4
|
Altman, I. (1977). Privacy Regulation: Culturally Universal or Culturally Specific? Journal of Social Issues, 33(3), 66--84.
|
| |
5
|
Rogério de Paula , Xianghua Ding , Paul Dourish , Kari Nies , Ben Pillet , David F. Redmiles , Jie Ren , Jennifer A. Rode , Roberto Silva Filho, In the eye of the beholder: a visualization-based approach to information system security, International Journal of Human-Computer Studies, v.63 n.1-2, p.5-24, July 2005
[doi> 10.1016/j.ijhcs.2005.04.021]
|
 |
6
|
Rogério de Paula , Xianghua Ding , Paul Dourish , Kari Nies , Ben Pillet , David Redmiles , Jie Ren , Jennifer Rode , Roberto Silva Filho, Two experiences designing for effective security, Proceedings of the 2005 symposium on Usable privacy and security, p.25-34, July 06-08, 2005, Pittsburgh, Pennsylvania
[doi> 10.1145/1073001.1073004]
|
 |
7
|
|
| |
8
|
Dourish, P. and Anderson, K. In press. Collective Information Practice: Exploring Privacy and Security as Social and Cultural Phenomena. Human-Computer Interaction.
|
| |
9
|
Goland, Y., E. J. Whitehead, et al. (1999). HTTP Extensions for Distributed Authoring -- WEBDAV, Internet Engineering Task Force: 1--94, RFC 2518.
|
 |
10
|
William C. Hill , James D. Hollan , Dave Wroblewski , Tim McCandless, Edit wear and read wear, Proceedings of the SIGCHI conference on Human factors in computing systems, p.3-9, May 03-07, 1992, Monterey, California, United States
[doi> 10.1145/142750.142751]
|
 |
11
|
|
| |
12
|
Plummer, D. C. (1986). Ethernet Address Resolution Protocol: Or converting network protocol addresses to 48.bit Ethernet address for transmission on Ethernet hardware, IETF RFC826.
|
 |
13
|
|
| |
14
|
Steinberg, D. and S. Cheshire (2005). Zero Configuration Networking: The Definitive Guide. O'Reilly Media.
|
| |
15
|
|
CITED BY
|
Robert W. Reeder , Lujo Bauer , Lorrie Faith Cranor , Michael K. Reiter , Kelli Bacon , Keisha How , Heather Strong, Expandable grids for visualizing and authoring computer security policies, Proceeding of the twenty-sixth annual SIGCHI conference on Human factors in computing systems, April 05-10, 2008, Florence, Italy
|
INDEX TERMS
Primary Classification:
H.
Information Systems
H.5
INFORMATION INTERFACES AND PRESENTATION (I.7)
H.5.1
Multimedia Information Systems
Subjects:
Evaluation/methodology
Additional Classification:
K.
Computing Milieux
K.4
COMPUTERS AND SOCIETY
K.4.4
Electronic Commerce
Subjects:
Security
General Terms:
Design,
Experimentation,
Human Factors,
Security
Keywords:
configuration in action,
dynamic visualizations,
effective security,
history,
peer-to-peer file sharing,
theoretical security,
usable security,
user and media characterization,
user study
|