Instead of only considering technology, computer security research now strives to also take into account the human factor by studying regular users and, to a lesser extent, experts like operators and developers of systems. We focus our analysis on the research on the crucial population of experts, whose human errors can impact many systems at once, and compare it to research on regular users. To understand how far we advanced in the area of human factors, how the field can further mature, and to provide a point of reference for researchers new to this field, we analyzed the past decade of human factors research in security and privacy, identifying 557 relevant publications. Of these, we found 48 publications focused on expert users and analyzed all in depth. For additional insights, we compare them to a stratified sample of 48 end-user studies. In this paper we investigate: (i) The perspective on human factors, and how we can learn from safety science (ii) How and who are the participants recruited, and how this -- as we find -- creates a western-centric perspective (iii) Research objectives, and how to align these with the chosen research methods (iv) How theories can be used to increase rigor in the communities scientific work, including limitations to the use of Grounded Theory, which is often incompletely applied (v) How researchers handle ethical implications, and what we can do to account for them more consistently Although our literature review has limitations, new insights were revealed and avenues for further research identified.
翻译:计算机安全研究现在不是仅仅考虑技术,而是努力通过研究定期用户,在较低程度上研究系统操作者和开发者等专家,来考虑人的因素。我们的分析侧重于专家的关键群体,这些专家的人类错误会同时影响许多系统,并将这种分析与经常用户的研究进行比较。为了了解我们在人类因素领域的进展程度,这个领域如何进一步成熟,并为这个领域的新研究人员提供一个参照点,我们分析了过去十年在安全和隐私方面的人类因素研究,确定了557份相关出版物。在这些出版物中,我们发现有48份出版物以专家用户为重点,并深入分析了所有出版物。为了更多的了解,我们将这些出版物与48项最终用户研究的分层抽样进行比较。在本文中,我们调查:(一) 人类因素的观点,以及我们如何从安全科学领域学习;(二) 如何和谁是参与者,以及我们所发现的情况如何创造以西方为中心的新视角(三) 研究目标,以及如何使这些出版物与所选择的研究方法相一致。 (四) 如何利用理论来提高社区内部用户的严谨度,我们如何运用这些理论,我们如何持续地评估这些研究的局限性。