This is joint work between myself and my co-author, Vivien Rooney. I’m a computer scientist, and Vivien’s an applied psychologist. We’re interested in understanding how humans experience working with security protocols. And, when I use the word “security protocol”, I mean it in the most general sense: a set of rules that people and machines are supposed to follow.
Understanding the human in computer security through Qualitative Research aims at a conceptual repositioning. The aim is to leverage individual human experience to understand and improve the impact of humans in computer security. Embracing what is particular, complex and subtle in the human social experience means understanding precisely what is happening when people transgress protocols. Repositioning transgression as normal, by researching what people working in Computer Network Defense do, how they construct an understanding of what they do, and why they do it, facilitates addressing the human aspects of this work on its own terms. Leveraging the insights developed through Qualitative Research means that it is possible to envisage and develop appropriate remedies using Applied Psychology, and thereby improve computer security.
The work of Computer Network Defense conducted, for instance, in Security Operations Centers and by Computer Security Incident Teams, is dependent not alone on technology, but also on people. Understanding how people experience these environments is an essential component toward achieving optimal functioning. This paper describes a qualitative research study on the human experience of working in these environments. Using Grounded Theory, a psychological understanding of the experience is developed. Results suggest that positive and negative aspects of the work are either amenable or not amenable to change. Areas of tension are identified, and posited as the focus for improving experience. For this purpose, psychological theories of Social Identity Theory, Relational Dialectics, and Cognitive Dissonance, provide a way of understanding and interpreting these components of Computer Network Defence work, and can be used to assess the experience of staff.
A challenge is to develop cyber-physical system scenarios that reflect the diversity and complexity of real-life cyber-physical systems in the research questions that they address. Time-bounded collaborative events, such as hackathons, jams and sprints, are increasingly used as a means of bringing groups of individuals together, in order to explore challenges and develop solutions. This paper describes our experiences, using a science hackathon to bring individual researchers together, in order to develop a common use-case implemented on a shared CPS testbed platform that embodies the diversity in their own security research questions. A qualitative study of the event was conducted, in order to evaluate the success of the process, with a view to improving future similar events.
Purpose In this paper, the authors consider how qualitative research techniques that are used in applied psychology to understand a person’s feelings and needs provides a means to elicit their security needs. Design/methodology/approach Recognizing that the codes uncovered during a grounded theory analysis of semi-structured interview data can be interpreted as policy attributes, the paper develops a grounded theory-based methodology that can be extended to elicit attribute-based access control style policies. In this methodology, user-participants are interviewed and machine learning is used to build a Bayesian network-based policy from the subsequent (grounded theory) analysis of the interview data. Findings Using a running example – based on a social psychology research study centered around photograph sharing – the paper demonstrates that in principle, qualitative research techniques can be used in a systematic manner to elicit security policy requirements. Originality/value While in principle qualitative research techniques can be used to elicit user requirements, the originality of this paper is a systematic methodology and its mapping into what is actionable, that is, providing a means to generate a machine-interpretable security policy at the end of the elicitation process.
Achieving informed consent in online and digital contexts is challenging for several reasons. One reason is that conveying the meaning and implications of agreements to individuals is hindered by legalistic formats obscuring the potential harm that can ensue from analytics of data collected in a socio-technical context, such as online. Furthermore, as technical capability advances, what can be achieved with data mining and initiatives outpaces statutory regulation, as well as the social norms that frame individual human understandings. It is argued that the paradigm that currently underpins informed consent in online settings draws on ethical positions that are either utilitarian or legalistic. In contrast, the adoption of an ethics of virtue approach as a new paradigm provides a framework for reconceptualising informed consent. Characteristics that are material for informed consent, shared by Online Analytics and Qualitative Longitudinal Research, provide the inspiration and basis for this interdisciplinary approach, with the application of lessons learned in the practice and theory of one discipline to another.
Recognising that the codes uncovered during a Grounded Theory analysis of semi-structured interview data can be interpreted as policy attributes, this paper describes how a Qualitative Research-based methodology can be extended to elicit Attribute Based Access Control style policies. In this methodology, user-participants are interviewed, and machine-learning is used to build a Bayesian Network based policy from the subsequent (Grounded Theory) analysis of the interview data.
Background Breast cancer continues to be a major public health problem for women. Early detection and treatment are key to improved outcomes. Whereas most women seek help promptly, some postpone seeking help for self-discovered breast symptoms. Investigation of women’s help-seeking behavior and the associated influencing factors on self-discovery of a breast symptom were sought. Objectives The aim of this article is to report the qualitative data from women who had self-discovered a breast symptom. Methods Women (n = 167) with a self-discovered breast symptom (who were part of a large quantitative correlational study) commented in an open-ended question on their overall experience. Comments were analyzed using Discourse Analysis. Results Four linked discourses were identified: (1) “being and remaining normal,” (2) “emotion,” (3) “becoming and being abnormal,” and (4) “rationality.” A sidelined discourse of emotion is drawn on to defer taking action based on rational knowledge. Conclusion The tension between discourses “emotion” and “rationality” further informs our understanding of women’s help-seeking behavior following self-discovered symptoms. Findings provide a deeper understanding of the emotional aspects of women’s experience around symptom discovery. Implications for Practice Findings will be of benefit to all healthcare professionals involved in assessment and screening of breast changes suggestive of breast cancer. They provide a novel insight into the meaning of breast cancer, its diagnosis and treatment, and how this impacts women’s emotions as they await consultation in a breast clinic.
Informed consent is a key issue in qualitative research. Conducting qualitative research longitudinally adds further complications to obtaining and maintaining informed consent. This paper illustrates how essential qualities of longitudinal research can be conceptualized as a resource to enhance ethical practice. In a research project on intimate relationships conducted with a cohort of participants, informed consent was addressed orally throughout the duration of the project. Following completion of the longitudinal data gathering, the formalities required as evidence of informed consent were only then conducted with each participant. With the written component of informed consent pending throughout the two year period of data collection, ongoing reflexivity during ethically important moments was enhanced. The author proposes that marking the conclusion of data gathering by obtaining written evidence of informed consent affords a means of enhancing ethical practice.
The normative security paradigm seeks to view a system as a society in which security is achieved by a combination of legislative provisions and normative behaviors. Drawing solely on legislative provisions is insufficient to achieve a just and orderly society. Similarly, security paradigms that focus solely on security policies and controls are insufficient. We argue that systems have analogous normative behaviors---behavioral norms---that are learnt from system logs.Using this analogy we explore how current theories about social norms in society can provide insight into using normative behavior in systems to help achieve security.
Grounded Theory provides a useful approach for eliciting and justifying subjective characteristics of individuals. A Grounded Theory analysis is carried on individuals who share pictures, with a view to developing a trust management policy model of indiscretion regarding the sharing of photographs.
Simon Foley合作论文数Department of Computer Science,;Computer Science,;University College7