DocumentCode
243494
Title
A Socio-technical Methodology for the Security and Privacy Analysis of Services
Author
Bella, Giampaolo ; Curzon, Paul ; Giustolisi, Rosario ; Lenzini, Gabriele
Author_Institution
Dipt. di Mat. e Inf., Univ. of Catania, Catania, Italy
fYear
2014
fDate
21-25 July 2014
Firstpage
401
Lastpage
406
Abstract
There is a widely accepted need for methodologies to verify the security of services. A typical service requires user data and then makes them available through the Internet independently from access platforms or user locations, but the layman is rarely aware of the entailed risks and seldom acts cautiously. The combined human-and-technology system is complex: it intertwines the technical protocols that establish the technical security properties, with the social protocols that regulate human attitudes to and behaviour with computers. A number of security threats are therefore inherently socio-technical. % An appropriate methodology to tackle security of web services from a socio-technical standpoint, namely when the human is in the loop, is still missing. This paper introduces one, termed the ceremony concertina traversal methodology. It advocates that technology is analysed in the presence of the human through the various structural layers that arise, from computer processes to user personas. Layers should be analysed individually then in combination, so as to transmit the guarantees that the technology is sound to its users in practical scenarios.
Keywords
Web services; data privacy; security of data; Web service security; ceremony concertina traversal methodology; security threats; sociotechnical methodology; user data privacy; Computers; Educational institutions; Electronic mail; Privacy; Protocols; Security; User interfaces; awareness; cloud; concertina; cybersecurity; modelling; security ceremony; verification;
fLanguage
English
Publisher
ieee
Conference_Titel
Computer Software and Applications Conference Workshops (COMPSACW), 2014 IEEE 38th International
Conference_Location
Vasteras
Type
conf
DOI
10.1109/COMPSACW.2014.69
Filename
6903163
Link To Document