Investigating System Operators' Perspective on Security Misconfigurations
Constanze Dietrich, Katharina Krombholz, Kevin Borgolte, Tobias Fiebig
摘要
Nowadays, security incidents have become a familiar "nuisance, " and they regularly lead to the exposure of private and sensitive data. The root causes for such incidents are rarely complex attacks. Instead, they are enabled by simple misconfigurations, such as authentication not being required, or security updates not being installed. For example, the leak of over 140 million Americans' private data from Equifax's systems is among most severe misconfigurations in recent history: The underlying vulnerability was long known, and a security patch had been available for months, but was never applied. Ultimately, Equifax blamed an employee for forgetting to update the affected system, highlighting his personal responsibility. In this paper, we investigate the operators' perspective on security misconfigurations to approach the human component of this class of security issues. We focus our analysis on system operators, who have not received significant attention by prior research. Hence, we investigate their perspective with an inductive approach and apply a multi-step empirical methodology: (i) a qualitative study to understand how to approach the target group and measure the misconfiguration phenomenon, and (ii) a quantitative survey rooted in the qualitative data. We then provide the first analysis of system operators' perspective on security misconfigurations, and we determine the factors that operators perceive as the root causes. Based on our findings, we provide practical recommendations on how to reduce security misconfigurations' frequency and impact.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper35
- Matched and Mismatched SOCs: A Qualitative Study on Security Operations Center IssuesFaris Bugra Kokulu, Ananta Soneji, Tiffany Bao, Yan Shoshitaishvili 等CCS 2019 · 被引用 134 次
- Effective Notification Campaigns on the Web: A Matter of Trust, Framing, and SupportMax Maass, Alina Stöver, Henning Pridöhl, Sebastian Bretthauer 等USENIX Security 2021 · 被引用 35 次
- Measuring and Mitigating the Risk of IP Reuse on Public CloudsEric Pauley, Ryan Sheatsley, Blaine Hoak, Quinn Burke 等S&P 2022 · 被引用 22 次
- Not that Simple: Email Delivery in the 21st CenturyFlorian Holzbauer, Johanna Ullrich, Martina Lindorfer, Tobias FiebigUSENIX ATC 2022 · 被引用 18 次
- Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare SectorNesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali BabarCSCW 2022 · 被引用 18 次
它引用的顶会 Paper10
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim 等S&P 2016 · 被引用 325 次
- MineSweeper: An In-depth Look into Drive-by Cryptocurrency Mining and Its DefenseRadhesh Krishnan Konoth, Emanuele Vineti, Veelasha Moonsamy, Martina Lindorfer 等CCS 2018 · 被引用 162 次
- Why Do Developers Get Password Storage Wrong?: A Qualitative Usability StudyAlena Naiakshina, Anastasia Danilova, Christian Tiefenau, Marco Herzog 等CCS 2017 · 被引用 146 次
- "I Have No Idea What I'm Doing" - On the Usability of Deploying HTTPSKatharina Krombholz, Wilfried Mayer, Martin Schmiedecker, Edgar R. WeipplUSENIX Security 2017 · 被引用 114 次
- SoK: Science, Security and the Elusive Goal of Security as a Scientific PursuitCormac Herley, Paul C. van OorschotS&P 2017 · 被引用 95 次
相关 Paper
- Mapping the Cloud: A Mixed-Methods Study of Cloud Security and Privacy Configuration ChallengesSumair Ijaz Hashmi, Shafay Kashif, Lea Gröber, Katharina Krombholz 等NDSS 2026 · 被引用 3 次
- Why Does Your Data Leak? Uncovering the Data Leakage in Cloud from Mobile AppsChaoshun Zuo, Zhiqiang Lin, Yinqian ZhangS&P 2019 · 被引用 123 次
- Who Left the Door Open? Investigating the Causes of Exposed IoT Devices in an Academic NetworkTakayuki Sasaki, Takaya Noma, Yudai Morii, Toshiya Shimura 等S&P 2024 · 被引用 3 次
- Automatic Insecurity: Exploring Email Auto-configuration in the WildShushang Wen, Yiming Zhang, Yuxiang Shen, Bingyu Li 等NDSS 2025
- The File That Contained the Keys Has Been Removed: An Empirical Analysis of Secret Leaks in Cloud Buckets and Responsible Disclosure OutcomesSoufian El Yadmani, Olga Gadyatskaya, Yury ZhauniarovichS&P 2025
