Measuring Security Practices.
Users are encouraged to adopt a wide array of technologies and behaviors to reduce their security risk. However, the adoption of these "best practices," ranging from the use of antivirus products to keeping software updated, is not well understood, nor is their practical impact on security risk well...
| Published in: | Communications of the ACM Vol. 65; no. 9; pp. 93 - 103 |
|---|---|
| Main Authors: | , , , , , , , , |
| Format: | Article |
| Published: |
Association for Computing Machinery
Sep2022
|
| Subjects: | |
| Online Access: | View this record in EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=158687864&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 158687864 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Sep2022 vid: 65 iid: 9 pid: 68 pub: Association for Computing Machinery artinfo: ui: 158687864 10.1145/3547133 ppf: 93 ppct: 10 formats: tig: atl: Measuring Security Practices. aug: au: DeKoven, Louis F. Randall, Audrey Mirian, Ariana Akiwate, Gautam Blume, Ansel Saul, Lawrence K. Schulman, Aaron Voelker, Geoffrey M. Savage, Stefan affil: University of California, San Diego, CA, USA su: Computer network security Antivirus software Best practices Software upgrades Computer users Privacy Computer software Computer operating systems sug: subj: Computer network security Antivirus software Best practices Software upgrades Computer users Privacy Computer software Computer operating systems ab: Users are encouraged to adopt a wide array of technologies and behaviors to reduce their security risk. However, the adoption of these "best practices," ranging from the use of antivirus products to keeping software updated, is not well understood, nor is their practical impact on security risk well established. To explore these issues, we conducted a large-scale measurement of 15,000 computers over six months. We use passive monitoring to infer and characterize the prevalence of various security practices as well as a range of other potentially security-relevant behaviors. We then explore the extent to which differences in key security behaviors impact the real-world outcomes (i.e., that a device shows clear evidence of having been compromised). pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2022 holdings: @attributes: islocal: N |
|---|