liu.seSearch for publications in DiVA
Change search
ReferencesLink to record
Permanent link

Direct link
Usability and security of personal firewalls
Linköping University, The Institute of Technology. Linköping University, Department of Computer and Information Science, Database and information techniques.
Linköping University, Department of Computer and Information Science, Database and information techniques. Linköping University, The Institute of Technology.
2007 (English)In: New Approaches for Security, Privacy and Trust in Complex Environments, 2007, 37-48 p.Chapter in book (Other academic)
Abstract [en]

Effective security of a personal firewall depends on (1) the rule granularity and the implementation of the rule enforcement and (2) the correctness and granularity of user decisions at the time of an alert. A misconfigured or loosely configured firewall may be more dangerous than no firewall at all because of the user’s false sense of security. This study assesses effective security of 13 personal firewalls by comparing possible granularity of rules as well as the usability of rule set-up and its influence on security.

In order to evaluate usability, we have submitted each firewall to use cases that require user decisions and cause rule creation. In order to evaluate the firewalls’ security, we analysed the created rules. In addition, we ran a port scan and replaced a legitimate, network-enabled application with another program to assess the firewalls’ behaviour in misuse cases. We have conducted a cognitive walkthrough paying special attention to user guidance and user decision support.

We conclude that a stronger emphasis on user guidance, on conveying the design of the personal firewall application, on the principle of least privilege and on implications of default settings would greatly enhance both usability and security of personal firewalls.

Place, publisher, year, edition, pages
2007. 37-48 p.
, IFIP International Federation for Information Processing, ISSN 1571-5736 (print) 1861-2288 (online) ; Vol 232
National Category
Computer Science
URN: urn:nbn:se:liu:diva-14434DOI: 10.1007/978-0-387-72367-9_4ISBN: 978-0-387-72366-2ISBN: 978-0-387-72367-9OAI: diva2:23499
Available from: 2007-04-27 Created: 2007-04-27 Last updated: 2014-06-24Bibliographically approved
In thesis
1. Usable Security Policies for Runtime Environments
Open this publication in new window or tab >>Usable Security Policies for Runtime Environments
2007 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

The runtime environments provided by application-level virtual machines such as the Java Virtual Machine or the .NET Common Language Runtime are attractive for Internet application providers because the applications can be deployed on any platform that supports the target virtual machine. With Internet applications, organisations as well as end users face the risk of viruses, trojans, and denial of service attacks. Virtual machine providers are aware of these Internet security risks and provide, for example, runtime monitoring of untrusted code and access control to sensitive resources.

Our work addresses two important security issues in runtime environments. The first issue concerns resource or release control. While many virtual machines provide runtime access control to resources, they do not provide any means of limiting the use of a resource once access is granted; they do not provide so-called resource control. We have addressed the issue of resource control in the example of the Java Virtual Machine. In contrast to others’ work, our solution builds on an enhancement to the existing security architecture. We demonstrate that resource control permissions for Java-mediated resources can be integrated into the regular Java security architecture, thus leading to a clean design and a single external security policy.

The second issue that we address is the usability

DiVA Web Form and security of the setup of security policies for runtime environments. Access control decisions are based on external configuration files, the security policy, which must be set up by the end user. This set-up is security-critical but also complicated and errorprone for a lay end user and supportive, usable tools are so far missing. After one of our usability studies signalled that offline editing of the configuration file is inefficient and difficult for end users, we conducted a usability study of personal firewalls to identify usable ways of setting up a security policy at runtime. An analysis of general user help techniques together with the results from the two previous studies resulted in a proposal of design guidelines for applications that need to set up a security policy. Our guidelines have been used for the design and implementation of the tool JPerM that sets the Java security policy at runtime. JPerM evaluated positively in a usability study and supports the validity of our design guidelines.

Place, publisher, year, edition, pages
Institutionen för datavetenskap, 2007
Linköping Studies in Science and Technology. Dissertations, ISSN 0345-7524 ; 1075
Information security, Usability, Java, Resource control, Virtual machine
National Category
Computer Science
urn:nbn:se:liu:diva-8809 (URN)978-91-85715-65-7 (ISBN)
Public defence
2007-05-29, Visionen, Hus B, Campus Valla, Linköpings universitet, Linköping, 10:15 (English)
Available from: 2007-04-27 Created: 2007-04-27 Last updated: 2009-04-29

Open Access in DiVA

No full text

Other links

Publisher's full textLink to Ph.D. Thesisfind book at a swedish library/hitta boken i ett svenskt bibliotek

Search in DiVA

By author/editor
Herzog, AlmutShahmehri, Nahid
By organisation
The Institute of TechnologyDatabase and information techniques
Computer Science

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

Altmetric score

Total: 182 hits
ReferencesLink to record
Permanent link

Direct link