As users increasingly introduce Internet-connected devices into their homes, having access to accurate and relevant cyber security information is a fundamental means of ensuring safe use. Given the paucity of information provided with many devices at the time of purchase, this paper engages in a critical study of the type of advice that home Internet of Things (IoT) or smart device users might be presented with on the Internet to inform their cyber security practices. We base our research on an analysis of 427 web pages from 234 organisations that present information on security threats and relevant cyber security advice. The results show that users searching online for information are subject to an enormous range of advice and news from various sources with differing levels of credibility and relevance. With no clear explanation of how a user may assess the threats as they are pertinent to them, it becomes difficult to understand which pieces of advice would be the most effective in their situation. Recommendations are made to improve the clarity, consistency and availability of guidance from recognised sources to improve user access and understanding.
翻译:由于用户越来越多地将互联网连接设备引入家中,获得准确和相关的网络安全信息是确保安全使用的基本手段;鉴于在购买时缺乏许多设备的信息,本文件对互联网用户或智能设备用户在互联网上可能提供何种建议以告知其网络安全做法进行批判性研究;我们的研究基于对234个组织提供的427个网页的分析,这些网页提供关于安全威胁的信息和相关网络安全建议;结果显示,在线搜索信息的用户需要来自不同程度的可信和相关性的不同来源的大量咨询和信息;如果没有明确解释用户如何评估与其相关的威胁,那么很难理解哪些建议对其处境最为有效;建议提高来自公认来源的指南的清晰度、一致性和可用性,以改善用户的获取和理解。