Finding and resolving security misusability with misusability cases.
Saved in:
| Title: | Finding and resolving security misusability with misusability cases. |
|---|---|
| Authors: | Faily, Shamal1 sfaily@bournemouth.ac.uk, Fléchais, Ivan2 |
| Source: | Requirements Engineering. Jun2016, Vol. 21 Issue 2, p209-223. 15p. |
| Subjects: | Use cases (Systems engineering), Systems engineering, Systems theory, Dynamic programming, Systems design, Electronic data processing |
| Abstract: | Although widely used for both security and usability concerns, scenarios used in security design may not necessarily inform the design of usability, and vice-versa. One way of using scenarios to bridge security and usability involves explicitly describing how design decisions can lead to users inadvertently exploiting vulnerabilities to carry out their production tasks. This paper describes how misusability cases, scenarios that describe how design decisions may lead to usability problems subsequently leading to system misuse, address this problem. We describe the related work upon which misusability cases are based before presenting the approach, and illustrating its application using a case study example. Finally, we describe some findings from this approach that further inform the design of usable and secure systems. [ABSTRACT FROM AUTHOR] |
| Copyright of Requirements Engineering is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract. (Copyright applies to all Abstracts.) | |
| Database: | Engineering Source |
| FullText | Links: – Type: pdflink Text: Availability: 0 |
|---|---|
| Header | DbId: egs DbLabel: Engineering Source An: 115423830 AccessLevel: 6 PubType: Academic Journal PubTypeId: academicJournal PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Finding and resolving security misusability with misusability cases. – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Faily%2C+Shamal%22">Faily, Shamal</searchLink><relatesTo>1</relatesTo><i> sfaily@bournemouth.ac.uk</i><br /><searchLink fieldCode="AR" term="%22Fléchais%2C+Ivan%22">Fléchais, Ivan</searchLink><relatesTo>2</relatesTo> – Name: TitleSource Label: Source Group: Src Data: <searchLink fieldCode="JN" term="%22Requirements+Engineering%22">Requirements Engineering</searchLink>. Jun2016, Vol. 21 Issue 2, p209-223. 15p. – Name: Subject Label: Subjects Group: Su Data: <searchLink fieldCode="DE" term="%22Use+cases+%28Systems+engineering%29%22">Use cases (Systems engineering)</searchLink><br /><searchLink fieldCode="DE" term="%22Systems+engineering%22">Systems engineering</searchLink><br /><searchLink fieldCode="DE" term="%22Systems+theory%22">Systems theory</searchLink><br /><searchLink fieldCode="DE" term="%22Dynamic+programming%22">Dynamic programming</searchLink><br /><searchLink fieldCode="DE" term="%22Systems+design%22">Systems design</searchLink><br /><searchLink fieldCode="DE" term="%22Electronic+data+processing%22">Electronic data processing</searchLink> – Name: Abstract Label: Abstract Group: Ab Data: Although widely used for both security and usability concerns, scenarios used in security design may not necessarily inform the design of usability, and vice-versa. One way of using scenarios to bridge security and usability involves explicitly describing how design decisions can lead to users inadvertently exploiting vulnerabilities to carry out their production tasks. This paper describes how misusability cases, scenarios that describe how design decisions may lead to usability problems subsequently leading to system misuse, address this problem. We describe the related work upon which misusability cases are based before presenting the approach, and illustrating its application using a case study example. Finally, we describe some findings from this approach that further inform the design of usable and secure systems. [ABSTRACT FROM AUTHOR] – Name: AbstractSuppliedCopyright Label: Group: Ab Data: <i>Copyright of Requirements Engineering is the property of Springer Nature and its content may not be copied or emailed to multiple sites without the copyright holder's express written permission. Additionally, content may not be used with any artificial intelligence tools or machine learning technologies. However, users may print, download, or email articles for individual use. This abstract may be abridged. No warranty is given about the accuracy of the copy. Users should refer to the original published version of the material for the full abstract.</i> (Copyright applies to all Abstracts.) |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=egs&AN=115423830 |
| RecordInfo | BibRecord: BibEntity: Identifiers: – Type: doi Value: 10.1007/s00766-014-0217-8 Languages: – Code: eng Text: English PhysicalDescription: Pagination: PageCount: 15 StartPage: 209 Subjects: – SubjectFull: Use cases (Systems engineering) Type: general – SubjectFull: Systems engineering Type: general – SubjectFull: Systems theory Type: general – SubjectFull: Dynamic programming Type: general – SubjectFull: Systems design Type: general – SubjectFull: Electronic data processing Type: general Titles: – TitleFull: Finding and resolving security misusability with misusability cases. Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Faily, Shamal – PersonEntity: Name: NameFull: Fléchais, Ivan IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 06 Text: Jun2016 Type: published Y: 2016 Identifiers: – Type: issn-print Value: 09473602 Numbering: – Type: volume Value: 21 – Type: issue Value: 2 Titles: – TitleFull: Requirements Engineering Type: main |
| ResultId | 1 |