CISPA
Browse

Investigating System Operators' Perspective on Security Misconfigurations

Download (1.5 MB)
conference contribution
posted on 2023-11-29, 18:08 authored by Constanze Dietrich, Katharina KrombholzKatharina Krombholz, Kevin Borgolte, Tobias Fiebig
Nowadays, security incidents have become a familiar “nuisance,” and they regularly lead to the exposure of private and sensitive data. The root causes for such incidents are rarely complex attacks. Instead, the attacks are straight-forward, and they are enabled by simple misconfigurations, such as authentication not being required, or security updates not being installed. For example, the leak of over 140 million Americans’ private data from Equifax’s systems ranks among most severe misconfigurations in recent history: The underlying vulnerability was long known, and a security patch had been readily available for months, but it was never applied. Ultimately, Equifax blamed an employee for forgetting to update the affected system, highlighting the personal responsibility of that operator. In this paper, we investigate the operators’ perspective on security misconfigurations to approach the human component of this class of security issues. We focus our analysis on system operators, as although they are the relevant actors managing the affected systems, they have not yet received significant attention by prior research. We follow an inductive approach and apply a multi-step empirical methodology: (i) a qualitative study to understand how to approach the target group and measure the misconfiguration phenomenon, and (ii) a quantitative survey rooted in the qualitative data. We then provide the first analysis of system operators’ perspective on security misconfigurations, and we determine the factors that operators perceive as the root causes. Based on our findings, we provide practical recommendations on how to reduce security misconfigurations’ frequency and impact.

History

Preferred Citation

Constanze Dietrich, Katharina Krombholz, Kevin Borgolte and Tobias Fiebig. Investigating System Operators' Perspective on Security Misconfigurations. In: ACM Conference on Computer and Communications Security (CCS). 2018.

Primary Research Area

  • Empirical and Behavioral Security

Name of Conference

ACM Conference on Computer and Communications Security (CCS)

Legacy Posted Date

2018-10-23

Open Access Type

  • Unknown

BibTeX

@inproceedings{cispa_all_2729, title = "Investigating System Operators' Perspective on Security Misconfigurations", author = "Dietrich, Constanze and Krombholz, Katharina and Borgolte, Kevin and Fiebig, Tobias", booktitle="{ACM Conference on Computer and Communications Security (CCS)}", year="2018", }

Usage metrics

    Categories

    No categories selected

    Exports

    RefWorks
    BibTeX
    Ref. manager
    Endnote
    DataCite
    NLM
    DC