field study

file

Visible to the public Use of Phishing Training to Improve Security Warning Compliance: Evidence From a Field Experiment

ABSTRACT: The current approach to protect users from phishing attacks is to display a warning when the webpage is considered suspicious. We hypothesize that users are capable of making correct informed decisions when the warning also conveys the reasons why it is displayed.

file

Visible to the public Deploying the Security Behavior Observatory: An Infrastructure for Long-term Monitoring of Client Machines

Abstract: Much of the data researchers usually collect about users' privacy and security behavior comes from short-term studies and focuses on specific, narrow activities. We present a design architecture and deployment of the Security Behavior Observatory (SBO), a client-server infrastructure designed to collect a wide array of data on user and computer security- and privacy-related behavior from a panel of hundreds of participants over several years. The SBO infrastructure had to be carefully designed to fulfill several requirements.