Zur Kurzanzeige

Behavioral Studies with IT-Administrators - Updating in Complex Environments and Securing Web Servers

dc.contributor.advisorSmith, Matthew
dc.contributor.authorTiefenau, Christian
dc.date.accessioned2021-03-25T15:46:25Z
dc.date.available2021-03-25T15:46:25Z
dc.date.issued25.03.2021
dc.identifier.urihttps://hdl.handle.net/20.500.11811/9005
dc.description.abstractUp until the turn of the millennium, research in the field of IT security mainly focused on the technical aspects of security mechanisms. Since then, the human factor has become more and more important and sparked research in the very broad field of usable security and privacy. In this field, researchers study the human-aspects of security systems, such as understanding security mechanisms and user-behavior when it comes to picking passwords or updating their systems.
While these works mainly focused on end users, recently, expert users have become the subject of research as well. In understanding developers and administrators, we can identify problems they face in performing security-relevant tasks and developing systems that support them, resulting in enhanced system security.
This thesis extends the field of usable security research and presents the results of four studies involving IT-administrators and expert users, which focus on the update processes in corporate contexts and the TLS setup step in the web server configuration.
The first study analyzes the update process of administrators in companies. This study also reveals obstacles that occur at various points in this process, which can be a reason for delaying or not deploying updates.
Based on the emerged process model, I further present a case study in which I apply the model to update processes of a web development company. The results show that the process is far more flexible than originally thought, leading to an adapted version of this model.
Subsequently, I present the findings of a study related to the importance of specific components in update release notes.
The findings of these three studies serve as a foundation to spark future work, e.g., in researching better communication strategies of the changes an update brings or finding ways to reduce the delay of updates by preventing downtimes.
Following the update topic, I present a study on the analysis of the automation effect in the TLS configuration process. The automated approach was found to have a positive impact on the security of the configuration. Through this study, I present lessons learned and discuss areas where the automated approach's principles can further enable better usability and security in the context of IT-administration.
en
dc.language.isoeng
dc.rightsIn Copyright
dc.rights.urihttp://rightsstatements.org/vocab/InC/1.0/
dc.subjectUsable Security
dc.subjectAdministrator Studies
dc.subjectHTTPS
dc.subjectAutomation
dc.subject.ddc004 Informatik
dc.titleBehavioral Studies with IT-Administrators - Updating in Complex Environments and Securing Web Servers
dc.typeDissertation oder Habilitation
dc.publisher.nameUniversitäts- und Landesbibliothek Bonn
dc.publisher.locationBonn
dc.rights.accessRightsopenAccess
dc.identifier.urnhttps://nbn-resolving.org/urn:nbn:de:hbz:5-61710
ulbbn.pubtypeErstveröffentlichung
ulbbnediss.affiliation.nameRheinische Friedrich-Wilhelms-Universität Bonn
ulbbnediss.affiliation.locationBonn
ulbbnediss.thesis.levelDissertation
ulbbnediss.dissID6171
ulbbnediss.date.accepted17.03.2021
ulbbnediss.instituteMathematisch-Naturwissenschaftliche Fakultät : Fachgruppe Informatik / Institut für Informatik
ulbbnediss.fakultaetMathematisch-Naturwissenschaftliche Fakultät
dc.contributor.coRefereeKrombholz, Katharina
ulbbnediss.contributor.orcidhttps://orcid.org/0000-0002-0904-1437


Dateien zu dieser Ressource

Thumbnail

Das Dokument erscheint in:

Zur Kurzanzeige

Die folgenden Nutzungsbestimmungen sind mit dieser Ressource verbunden:

InCopyright