Hier finden Sie wissenschaftliche Publikationen aus den Fraunhofer-Instituten.

Heuristics and Models for Evaluating the Usability of Security Measures

: Feth, Denis; Polst, Svenja


Alt, Florian (Hrsg.) ; Association for Computing Machinery -ACM-:
Mensch und Computer, MuC 2019. Tagungsband : Thema "Neue Digitale Realitäten"; 8. bis 11. September 2019, Hamburg
New York: ACM, 2019
ISBN: 978-1-4503-7198-8
Konferenz "Mensch & Computer" (M&C) <19, 2019, Hamburg>
Bundesministerium für Bildung und Forschung BMBF (Deutschland)
01IS12053; Software Campus
Conference Paper
Fraunhofer IESE ()
Usable Security; Quality Model; Usability Evaluation; Heuristic Evaluation; Human-centered Design

Security mechanisms are nowadays part of almost every software. At the same time, they are typically sociotechnical and require involvement of end users to be effective. The usability of security measures is thus an essential factor. Despite this importance, this aspect often does not receive the necessary attention, for example due to short resources like time, budget, or usability experts. In the worst-case, users reject or circumvent even strong security measures and technically secure systems become insecure. To tackle the problem of unusable security measures, we developed a heuristics-based usability evaluation and optimization approach for security measures. In order to make heuristics applicable also for non-usability experts, we enrich them with information from a joint model for usability and security. In particular, this
approach allows developers and administrators to perform usability evaluations and thus enables an early tailoring to the user, complementary to expert or user reviews. In this paper, we present our approach, including an initial set of heuristics, a joint model for usability and security and a set of mapping rules that combine heuristics and model. We evaluated the applicability of our approach, which we present in this paper.