Position: the user is the enemy

  • Authors:
  • S. Vidyaraman;M. Chandrasekaran;S. Upadhyaya

  • Affiliations:
  • University at Buffalo, Buffalo;University at Buffalo, Buffalo;University at Buffalo, Buffalo

  • Venue:
  • NSPW '07 Proceedings of the 2007 Workshop on New Security Paradigms
  • Year:
  • 2008

Quantified Score

Hi-index 0.00

Visualization

Abstract

The Human Factor has long been recognized as the weakest link in computer systems security, yet, nothing technically significant has been done to address this problem in an attack agnostic manner. In this paper, we introduce the mantra of "The User is the Enemy" for security designers and developers alike as an underlying current towards addressing the weak human factor. We present different notions of the user and the system and argue from parallel tracks that user actions, both ignorant and non-compliant, are detrimental to the organization. We further show how the paradigm has been applied in a rather unconscious manner and contend that security mechanisms borne out of a conscious application will be more effective towards addressing this systemic problem. Our position is not meant to be a cynical attitude towards users; rather, it is meant to be the focal point of security design attitude, similar to the mantra "All user input is evil" for addressing buffer overflow attacks.