TY - GEN
T1 - Position
T2 - 2007 Workshop on New Security Paradigms, NSPW 2007
AU - Vidyaraman, S.
AU - Chandrasekaran, M.
AU - Upadhyaya, S.
PY - 2007
Y1 - 2007
N2 - The Human Factor has long been recognized as the weakest link in computer systems security, yet, nothing technically significant has been done to address this problem in an attack agnostic manner. In this paper, we introduce the mantra of "The User is the Enemy" for security designers and developers alike as an underlying current towards addressing the weak human factor. We present different notions of the user and the system and argue from parallel tracks that user actions, both ignorant and non-compliant, are detrimental to the organization. We further show how the paradigm has been applied in a rather unconscious manner and contend that security mechanisms borne out of a conscious application will be more effective towards addressing this systemic problem. Our position is not meant to be a cynical attitude towards users; rather, it is meant to be the focal point of security design attitude, similar to the mantra "All user input is evil" for addressing buffer overflow attacks.
AB - The Human Factor has long been recognized as the weakest link in computer systems security, yet, nothing technically significant has been done to address this problem in an attack agnostic manner. In this paper, we introduce the mantra of "The User is the Enemy" for security designers and developers alike as an underlying current towards addressing the weak human factor. We present different notions of the user and the system and argue from parallel tracks that user actions, both ignorant and non-compliant, are detrimental to the organization. We further show how the paradigm has been applied in a rather unconscious manner and contend that security mechanisms borne out of a conscious application will be more effective towards addressing this systemic problem. Our position is not meant to be a cynical attitude towards users; rather, it is meant to be the focal point of security design attitude, similar to the mantra "All user input is evil" for addressing buffer overflow attacks.
KW - Non-compliant users
KW - User centered security
UR - https://www.scopus.com/pages/publications/70450246983
U2 - 10.1145/1600176.1600189
DO - 10.1145/1600176.1600189
M3 - Conference contribution
AN - SCOPUS:70450246983
SN - 9781605580807
T3 - Proceedings New Security Paradigms Workshop
SP - 75
EP - 80
BT - Proceedings - New Security Paradigms Workshop 2007, NSPW 2007
Y2 - 18 September 2007 through 21 September 2007
ER -