Affiliation:
1. Purdue University, West Lafayette, Indiana, USA
Abstract
Objective: The overarching goal is to convey the concept of science of security and the contributions that a scientifically based, human factors approach can make to this interdisciplinary field. Background: Rather than a piecemeal approach to solving cybersecurity problems as they arise, the U.S. government is mounting a systematic effort to develop an approach grounded in science. Because humans play a central role in security measures, research on security-related decisions and actions grounded in principles of human information-processing and decision-making is crucial to this interdisciplinary effort. Method: We describe the science of security and the role that human factors can play in it, and use two examples of research in cybersecurity—detection of phishing attacks and selection of mobile applications—to illustrate the contribution of a scientific, human factors approach. Results: In these research areas, we show that systematic information-processing analyses of the decisions that users make and the actions they take provide a basis for integrating the human component of security science. Conclusion: Human factors specialists should utilize their foundation in the science of applied information processing and decision making to contribute to the science of cybersecurity.
Subject
Behavioral Neuroscience,Applied Psychology,Human Factors and Ergonomics
Cited by
60 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Where Do Users Look When Deciding If a Text Message is Safe or Malicious?;Proceedings of the Human Factors and Ergonomics Society Annual Meeting;2024-08-12
2. Human Factors in Cybersecurity;Advances in Information Security, Privacy, and Ethics;2024-06-30
3. Employee behavior: the psychological gateway for cyberattacks;Organizational Cybersecurity Journal: Practice, Process and People;2024-05-30
4. Toma de decisiones en la gestión de riesgos cibernéticos: una aproximación fenomenológico-hermenéutica;Innovar;2023-12-15
5. Cybersecurity Breach Case Study;Applied Research Approaches to Technology, Healthcare, and Business;2023-09-29