In recent years, many tools have been developed to understand attacks that make use of visualization, but few examples aims to predict real-world consequences. We have developed a visualization tool that aims to improve decision support during attacks. Our tool visualizes propagation of risks from IDS and AV-alert data by relating sensor alerts to Business Process (BP) tasks and machine assets: an important capability gap present in many Security Operation Centres (SOCs) today. In this paper we present a user study in which we evaluate the tool's usability and ability to deliver situational awareness to the analyst. Ten analysts from seven SOCs performed carefully designed tasks related to understanding risks and prioritising recovery decisions. The study was conducted in laboratory conditions, with simulated attacks, and used a mixed-method approach to collect data from questionnaires, eyetracking and voice-recorded interviews. The findings suggest that providing analysts with situational awareness relating to business priorities can help them prioritise response strategies. Finally, we provide an in-depth discussion on the wider questions related to user studies in similar conditions as well as lessons learned from our user study and developing a visualization tool of this type.
In order to design on-line services that are able to support the end-user in making informed choices about when and how to disclose personal information, a close understanding of the relationship between privacy and confidence is therefore needed. UK citizens accessing on-line services have privacy concerns about sharing personal information with government organizations. The physical distance between service user and service provider (increased by on-line service delivery) can reduce confidence in the management of personal information. A close understanding of the relationship between user confidence and information presentation can suggest new design principles to support them in making informed choices about when and how to disclose personal information. This paper presents the result of three user studies to understand user confidence with relation to graphical information presentation, which led to three distinct types of confidence: Institutional; Technological; and Relationship. The final study represents the impact of using graphical information presentation on users' privacy concern and their confidence in using on-line services. The result indicated service users' privacy concerns decrease when their privacy awareness increase.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.