Alsaleh Mansour, Alomar Noura, Alarifi Abdulrahman
King Abdulaziz City for Science and Technology (KACST), Riyadh, Kingdom of Saudi Arabia.
Software Engineering Department, King Saud University, Riyadh, Kingdom of Saudi Arabia.
PLoS One. 2017 Mar 15;12(3):e0173284. doi: 10.1371/journal.pone.0173284. eCollection 2017.
Protecting smartphones against security threats is a multidimensional problem involving human and technological factors. This study investigates how smartphone users' security- and privacy-related decisions are influenced by their attitudes, perceptions, and understanding of various security threats. In this work, we seek to provide quantified insights into smartphone users' behavior toward multiple key security features including locking mechanisms, application repositories, mobile instant messaging, and smartphone location services. To the best of our knowledge, this is the first study that reveals often unforeseen correlations and dependencies between various privacy- and security-related behaviors. Our work also provides evidence that making correct security decisions might not necessarily correlate with individuals' awareness of the consequences of security threats. By comparing participants' behavior and their motives for adopting or ignoring certain security practices, we suggest implementing additional persuasive approaches that focus on addressing social and technological aspects of the problem. On the basis of our findings and the results presented in the literature, we identify the factors that might influence smartphone users' security behaviors. We then use our understanding of what might drive and influence significant behavioral changes to propose several platform design modifications that we believe could improve the security levels of smartphones.
保护智能手机免受安全威胁是一个涉及人类和技术因素的多维度问题。本研究调查了智能手机用户与安全和隐私相关的决策如何受到他们对各种安全威胁的态度、认知和理解的影响。在这项工作中,我们试图对智能手机用户在多种关键安全功能(包括锁定机制、应用程序库、移动即时通讯和智能手机定位服务)方面的行为提供量化见解。据我们所知,这是第一项揭示各种与隐私和安全相关行为之间通常不可预见的关联和依赖性的研究。我们的工作还提供了证据,表明做出正确的安全决策不一定与个人对安全威胁后果的认知相关。通过比较参与者的行为以及他们采用或忽略某些安全措施的动机,我们建议实施额外的说服方法,重点解决该问题的社会和技术方面。基于我们的研究结果以及文献中呈现的结果,我们确定了可能影响智能手机用户安全行为的因素。然后,我们利用对可能推动和影响重大行为变化的因素的理解,提出了几项我们认为可以提高智能手机安全水平的平台设计修改建议。