论文标题
更安全:跨国组织中物联网设备风险评估框架的开发和评估
SAFER: Development and Evaluation of an IoT Device Risk Assessment Framework in a Multinational Organization
论文作者
论文摘要
物联网(IoT)设备的用户通常不知道其安全风险,并且无法充分考虑安全考虑。这使网络,基础架构和用户处于危险之中。我们开发和评估了Safer,这是一个物联网设备风险评估框架,旨在提高用户评估连接设备的安全性。我们在一个允许使用私人设备的大型跨国组织中部署了更安全的。为了评估框架,我们与20名员工进行了混合方法研究。我们的发现表明,更安全会提高用户对安全问题的认识。它提供了宝贵的建议并影响设备选择。根据我们的发现,我们讨论了对设备风险评估工具的设计的影响,特别是关于风险通信与用户对设备复杂性的看法之间的关系。
Users of Internet of Things (IoT) devices are often unaware of their security risks and cannot sufficiently factor security considerations into their device selection. This puts networks, infrastructure and users at risk. We developed and evaluated SAFER, an IoT device risk assessment framework designed to improve users' ability to assess the security of connected devices. We deployed SAFER in a large multinational organization that permits use of private devices. To evaluate the framework, we conducted a mixed-method study with 20 employees. Our findings suggest that SAFER increases users' awareness of security issues. It provides valuable advice and impacts device selection. Based on our findings, we discuss implications for the design of device risk assessment tools, with particular regard to the relationship between risk communication and user perceptions of device complexity.