Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness

The role of ICT system’s user should be taken into consideration when developing different information security solutions because user, as its constitutive element, can significantly affect overall system security with his/her potentially risky behaviour depending on the level of user’s security awa...

Full description

Bibliographic Details
Main Authors: Tomislav Galba, Kresimir Solic, Kresimir Nenadic
Format: Article
Language:English
Published: Faculty of Mechanical Engineering in Slavonski Brod, Faculty of Electrical Engineering in Osijek, Faculty of Civil Engineering in Osijek 2018-01-01
Series:Tehnički Vjesnik
Subjects:
Online Access:https://hrcak.srce.hr/file/293182
_version_ 1797207658155999232
author Tomislav Galba
Kresimir Solic
Kresimir Nenadic
author_facet Tomislav Galba
Kresimir Solic
Kresimir Nenadic
author_sort Tomislav Galba
collection DOAJ
description The role of ICT system’s user should be taken into consideration when developing different information security solutions because user, as its constitutive element, can significantly affect overall system security with his/her potentially risky behaviour depending on the level of user’s security awareness. In this paper authors propose risk assessment approach of ICT users’ behaviour based on the evidential reasoning technique. Performance testing was compared using combination of cluster analysis and discriminant analysis while empirical analysis was conducted on the total of 627 e-mail users grouped regarding gender, age, technical background knowledge and level of experience. Assessment methodology used in this paper has proven to be well suited for evaluation of users’ awareness and identification of their potentially risky behaviour. Results of empirical analysis showed that all groups of users got overall utility grade higher than the simulated "minimally enough aware" user, but less than “average awareness” grade. As users of all groups are highly critical towards collocutor, it can mean that users are quite aware about the importance of information security foundation, but also about lack of knowledge regarding different security issues. Another possible reason may be the users’ negligence toward security guidelines and protocols.
first_indexed 2024-04-24T09:26:24Z
format Article
id doaj.art-1b8fe15c315c4f0a96d5533189e10a8c
institution Directory Open Access Journal
issn 1330-3651
1848-6339
language English
last_indexed 2024-04-24T09:26:24Z
publishDate 2018-01-01
publisher Faculty of Mechanical Engineering in Slavonski Brod, Faculty of Electrical Engineering in Osijek, Faculty of Civil Engineering in Osijek
record_format Article
series Tehnički Vjesnik
spelling doaj.art-1b8fe15c315c4f0a96d5533189e10a8c2024-04-15T14:43:05ZengFaculty of Mechanical Engineering in Slavonski Brod, Faculty of Electrical Engineering in Osijek, Faculty of Civil Engineering in OsijekTehnički Vjesnik1330-36511848-63392018-01-0125230931510.17559/TV-20150513123751Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security AwarenessTomislav Galba0Kresimir Solic1Kresimir Nenadic2Faculty of Electrical Engineering, Computer Science and Information Technology Osijek, J. J. Strossmayer University of Osijek, Kneza Trpimira 2b, 31000 Osijek, CroatiaFaculty of Medicine, J. J. Strossmayer University of Osijek, Cara Hadrijana 10/E, 31000 Osijek, CroatiaFaculty of Electrical Engineering, Computer Science and Information Technology Osijek, J. J. Strossmayer University of Osijek, Kneza Trpimira 2b, 31000 Osijek, CroatiaThe role of ICT system’s user should be taken into consideration when developing different information security solutions because user, as its constitutive element, can significantly affect overall system security with his/her potentially risky behaviour depending on the level of user’s security awareness. In this paper authors propose risk assessment approach of ICT users’ behaviour based on the evidential reasoning technique. Performance testing was compared using combination of cluster analysis and discriminant analysis while empirical analysis was conducted on the total of 627 e-mail users grouped regarding gender, age, technical background knowledge and level of experience. Assessment methodology used in this paper has proven to be well suited for evaluation of users’ awareness and identification of their potentially risky behaviour. Results of empirical analysis showed that all groups of users got overall utility grade higher than the simulated "minimally enough aware" user, but less than “average awareness” grade. As users of all groups are highly critical towards collocutor, it can mean that users are quite aware about the importance of information security foundation, but also about lack of knowledge regarding different security issues. Another possible reason may be the users’ negligence toward security guidelines and protocols.https://hrcak.srce.hr/file/293182behavioural analysiscluster analysisevidential reasoning approachinformation securityusers’ awareness
spellingShingle Tomislav Galba
Kresimir Solic
Kresimir Nenadic
Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness
Tehnički Vjesnik
behavioural analysis
cluster analysis
evidential reasoning approach
information security
users’ awareness
title Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness
title_full Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness
title_fullStr Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness
title_full_unstemmed Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness
title_short Evidential Reasoning Approach to Behavioural Analysis of ICT Users’ Security Awareness
title_sort evidential reasoning approach to behavioural analysis of ict users security awareness
topic behavioural analysis
cluster analysis
evidential reasoning approach
information security
users’ awareness
url https://hrcak.srce.hr/file/293182
work_keys_str_mv AT tomislavgalba evidentialreasoningapproachtobehaviouralanalysisofictuserssecurityawareness
AT kresimirsolic evidentialreasoningapproachtobehaviouralanalysisofictuserssecurityawareness
AT kresimirnenadic evidentialreasoningapproachtobehaviouralanalysisofictuserssecurityawareness