• No se han encontrado resultados

Firewall information and security visualization : improving the usage and adoption of modern network firewalls by novice users

N/A
N/A
Protected

Academic year: 2023

Share "Firewall information and security visualization : improving the usage and adoption of modern network firewalls by novice users"

Copied!
94
0
0

Texto completo

This research focuses on personal firewalls because it is our belief, and I will show that personal firewalls are more vulnerable than those of large corporations. Our hypothesis for this research is that many of the users who install personal firewalls do not have the knowledge to configure them properly. We propose that the problem with a personal firewall is that most users do not have the correct conceptual models of the interaction between the computer, the firewall, and security in order to correctly configure these personal firewalls.

Our goal is to use information visualization 13] as a possible solution to the problems of novice users configuring their personal firewalls. This dissertation presents a new personal information visualization firewall designed and developed using a combination of human-computer interaction methodologies and techniques, information visualization 13] and the piccolo toolkit 19]. After completing studies on existing personal firewalls and knowledge of personal firewalls of novice users, we thought about possible visualization solutions and built a high-level prototype.

We then refined the prototype with conceptual model extraction and expert evaluations and developed the new information visualization personal firewall using the piccolo toolkit, Microsoft Visual Studio. We then tested the usability of the new information visualization personal firewall, and it was shown that visualization improves the use of novices to some extent, but design choices can be detrimental to the improvement of use.

Introduction

Introduction

  • What is a personal firewall?
  • Motivation
  • Aim
  • Methodologies and techniques
    • Evaluation methodologies
    • Design techniques
  • Dissertation outline

34;A personal firewall (sometimes called a desktop firewall) is a software application used to protect a single Internet-connected computer from intruders" [21]. The above headlines emphasize the need for the security provided by a personal firewall or firewalls in general The level of protection depends entirely on the effective configuration of the personal firewall.

The following section aims to explain a different approach to presenting personal firewall information so that beginners can configure their own personal firewalls. This qualitative data can be used to help design and develop new personal firewall information visualization. For example, in this research the artifact is the way in which the personal firewall is configured.

This qualitative data can also be used to help design and develop new personal firewall information visualization. This method also allows us to observe how useful the new personal firewall information visualization is based on the steps the user takes in trying to successfully complete a task.

Literature Review

Literature review

  • Introduction
  • Experiment 1: The study of existing personal firewalls or computer
  • Exploration of Existing Personal Firewalls
    • ZoneAlarm Pro
    • Norton Internet Security
    • Microsoft Windows firewall
  • Information Visualization Origins and Exploration of Its Techniques
    • Origins of Information Visualization
    • Information Visualization Techniques

Information obtained from the examination of interface structure can be used or modified in the future development of the new information visualization personal firewall design. Four of the more popular personal firewall or internet security packages were chosen to be explored. ZoneAlarm Pro also has potential aspects, including interface and security information structure, that may hinder the personal firewall configuration process for novice users.

This can cause some problems because the use of the open padlock and a stop sign is inconsistent. Using exceptions instead of program control could lead to a misunderstanding of the role of the exceptions. Network: The data used in our study is the same as network data because the data consists of items.

This network visualization will include a representation of the data used in our research data, which is network data. We will explore these representations of nodes and links to solve our problem of presenting our research network data in a way that is understandable and useful given our personal firewall configuration.

Methodology

Methodology

  • Introduction
  • Metaphor Development and Experiments
  • Experiments and Methodologies
    • Experiment 2: The study of novice user's personal firewall or
    • System Design: Brainstorming and paper prototyping
    • Experiment 3: Conceptual model extraction and expert evaluation

The six people who might meet the criteria of a novice personal firewall user are chosen based on certain criteria. The more technical security questions will be answered using conceptual model extraction [19] (if they did not have a personal firewall installed on their computer) or artifact walkthrough [6] if they did have a firewall installed. The extraction of the conceptual model will be carried out using screenshots from Panda Platinum Internet Security (see Figure 2.1).

The questionnaire will use a Likert rating scale (see Figure 3.1), where the interviewee will be asked to rate various statements from 1 to 5. This method will be used to observe the respondents' understanding of personal firewall icons and interfaces. Another result will be to gain insight into how much the novice user knows, or doesn't know, about firewalls.

Information obtained by interviewing and observing novices will be used to select designs and visualizations for the new information visualization personal firewall. The results and information from the previous experiments will be used to explore different visualization ideas. A metaphor brainstorming session will be held with four or five interface, visualization and computing experts.

The methodology that will be used in this system design session is user-centered design and the technique used is Paper Prototyping. This prototype will be based on the paper prototype that emerged from the metaphor brainstorming session during system design. The outcomes of this study will provide further information on the understandability and mental models of personal firewalls by novice users.

A number of tasks will be prepared and the interviewer will be expected to carry out these tasks. These observations and success or failure to complete the task will be documented and analyzed. The combination of quantitative results (Likert rating scale results) and qualitative results (the comments of each task performed) will be an indication of how useful the new information visualization personal firewall is.

Experiments, results and discussion

Experiments, results and discussion

  • Introduction
  • Summary of the experiment structure
  • Experiments and results
    • Experiment 1: The study of existing personal firewalls or
    • Experiment 2: The study of novice users' personal firewall or
    • System Design: Brainstorming and paper prototyping
    • Experiment 3: Conceptual model extraction and expert evaluation

Evaluation of the new information personal firewall visualization

Evaluation of the new information personal firewall visualization

  • Introduction
  • Screens hots of the visualization and how it works
  • Experiment 4: Task-Based evaluation of the new information personal
  • Experiment 4 conclusion

The screenshots shown in the figures below are of the new personal firewall for information visualization. Repetition of the twelve cyclical conceptual model extraction questions about the new personal firewall and its elements. This is done to check whether the interviewees are familiar with the elements and icons of the new information visualization personal firewall.

Similar to task 1, she can respond by observing the number on the tick, cross, or prompt button. The user should observe the color of the line connecting SMTP and MSN Messenger. On the application side, the top box of the Internet Explorer application node must be clicked to activate the bottom six-button panel, (see Figure 4.3).

The user will have to observe the color of the line connecting the Internet Explorer application to the SMTP port. These two methods are similar to those described in task 10, but the difference is that the task asks the user to change access to the MISCELLANEOUS port to a prompt mode that does not allow Skype to access all ports. It seems that most of the interviewees now have some understanding of what a gate is and what its functionality is.

In Figure 5.6, the graph shows that 95% of the respondents did not know what the speech bubble button represented. The purpose of the first task was to find out from the interviewees that applications are connected to a number of ports and vice versa. Knowing the bottom panel of the corresponding application or port buttons would lead the interviewee to the next three tasks.

The last three tasks aimed to make the interviewees discover the functionality of the big tick, X and the prompt buttons. However, this revealed the functionality of the checkbox, which is that it changes all connections to allow, for the interviewees. There were a few areas that affected the usability of the new personal firewall for information visualization.

Conclusion and future work

Conclusion and Future Work

  • Conclusion
    • Research Question One Conclusion
    • Research Question Two Conclusion
  • Future Work
    • Zoom Feature
    • Add or Remove, Application or Port Nodes
    • Refinement of Icons and Tick, Cross and Prompt Control Buttons. 75
    • Add this new information visualization personal firewall as an

In the cyclical conceptual model extraction experiment, users understood the iconic representations, which are the http icon, email icons, ticks, crosses, lines, etc. (see Section 4.3.4, Results: Answers to the conceptual model extraction questions), with the exception of prompt user icon. The question mark in a speech bubble was supposed to indicate a question posed to users, but the interviewees did not understand the meaning of the speech bubble in the context of personal firewall technology. The layout of the bottom panel of control buttons was not effective enough and detrimental to the interviewees' use of the new personal firewall information visualization, and this is the reason for .. 34;Is visualization the answer to improving the use of firewalls by novice users?".

However, in this study, the attempt to improve usability was not convincing, but we believe that with a few more design and testing iterations, long-term testing and testing of the visualization, it is possible to increase the effectiveness of the visualization. Benefits include being able to see the selected node and its connected children clearly, as the other nodes shrink, turn gray, and zoom back, highlighting the "Zoom and Filter 123)" portion of the visual search mantra. This feature allows the user to add or remove nodes from the application or port side of the visualization.

The refinement of the icons and the check, cross, and prompt buttons can improve the adoption of modern network firewalls by novice users. Connect the new Personal Firewall front-end for information visualization to the back-end of a Personal Firewall. 34;Why Johnny Can't Code: A Usability Case Study of PGP 5.0" Proceedings of the 8th USENIX Security Symposium.

Referencias

Documento similar

The aim of the present study was to determine if, from the perspective of the psychological dimension of friendship, the users of the Facebook social media network experience, or can