Finding and resolving security misusability with misusability cases.

Saved in:
Bibliographic Details
Title: Finding and resolving security misusability with misusability cases.
Authors: Faily, Shamal1 sfaily@bournemouth.ac.uk, Fléchais, Ivan2
Source: Requirements Engineering. Jun2016, Vol. 21 Issue 2, p209-223. 15p.
Subjects: Use cases (Systems engineering), Systems engineering, Systems theory, Dynamic programming, Systems design, Electronic data processing
Abstract: Although widely used for both security and usability concerns, scenarios used in security design may not necessarily inform the design of usability, and vice-versa. One way of using scenarios to bridge security and usability involves explicitly describing how design decisions can lead to users inadvertently exploiting vulnerabilities to carry out their production tasks. This paper describes how misusability cases, scenarios that describe how design decisions may lead to usability problems subsequently leading to system misuse, address this problem. We describe the related work upon which misusability cases are based before presenting the approach, and illustrating its application using a case study example. Finally, we describe some findings from this approach that further inform the design of usable and secure systems. [ABSTRACT FROM AUTHOR]
Copyright of Requirements Engineering is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.)
Database: Engineering Source
FullText Links:
  – Type: pdflink
Text:
  Availability: 0
Header DbId: egs
DbLabel: Engineering Source
An: 115423830
AccessLevel: 6
PubType: Academic Journal
PubTypeId: academicJournal
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Finding and resolving security misusability with misusability cases.
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Faily%2C+Shamal%22">Faily, Shamal</searchLink><relatesTo>1</relatesTo><i> sfaily@bournemouth.ac.uk</i><br /><searchLink fieldCode="AR" term="%22Fléchais%2C+Ivan%22">Fléchais, Ivan</searchLink><relatesTo>2</relatesTo>
– Name: TitleSource
  Label: Source
  Group: Src
  Data: <searchLink fieldCode="JN" term="%22Requirements+Engineering%22">Requirements Engineering</searchLink>. Jun2016, Vol. 21 Issue 2, p209-223. 15p.
– Name: Subject
  Label: Subjects
  Group: Su
  Data: <searchLink fieldCode="DE" term="%22Use+cases+%28Systems+engineering%29%22">Use cases (Systems engineering)</searchLink><br /><searchLink fieldCode="DE" term="%22Systems+engineering%22">Systems engineering</searchLink><br /><searchLink fieldCode="DE" term="%22Systems+theory%22">Systems theory</searchLink><br /><searchLink fieldCode="DE" term="%22Dynamic+programming%22">Dynamic programming</searchLink><br /><searchLink fieldCode="DE" term="%22Systems+design%22">Systems design</searchLink><br /><searchLink fieldCode="DE" term="%22Electronic+data+processing%22">Electronic data processing</searchLink>
– Name: Abstract
  Label: Abstract
  Group: Ab
  Data: Although widely used for both security and usability concerns, scenarios used in security design may not necessarily inform the design of usability, and vice-versa. One way of using scenarios to bridge security and usability involves explicitly describing how design decisions can lead to users inadvertently exploiting vulnerabilities to carry out their production tasks. This paper describes how misusability cases, scenarios that describe how design decisions may lead to usability problems subsequently leading to system misuse, address this problem. We describe the related work upon which misusability cases are based before presenting the approach, and illustrating its application using a case study example. Finally, we describe some findings from this approach that further inform the design of usable and secure systems. [ABSTRACT FROM AUTHOR]
– Name: AbstractSuppliedCopyright
  Label:
  Group: Ab
  Data: <i>Copyright of Requirements Engineering is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.)
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=115423830
RecordInfo BibRecord:
  BibEntity:
    Identifiers:
      – Type: doi
        Value: 10.1007/s00766-014-0217-8
    Languages:
      – Code: eng
        Text: English
    PhysicalDescription:
      Pagination:
        PageCount: 15
        StartPage: 209
    Subjects:
      – SubjectFull: Use cases (Systems engineering)
        Type: general
      – SubjectFull: Systems engineering
        Type: general
      – SubjectFull: Systems theory
        Type: general
      – SubjectFull: Dynamic programming
        Type: general
      – SubjectFull: Systems design
        Type: general
      – SubjectFull: Electronic data processing
        Type: general
    Titles:
      – TitleFull: Finding and resolving security misusability with misusability cases.
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Faily, Shamal
      – PersonEntity:
          Name:
            NameFull: Fléchais, Ivan
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 06
              Text: Jun2016
              Type: published
              Y: 2016
          Identifiers:
            – Type: issn-print
              Value: 09473602
          Numbering:
            – Type: volume
              Value: 21
            – Type: issue
              Value: 2
          Titles:
            – TitleFull: Requirements Engineering
              Type: main
ResultId 1