[Journal First] Model Comprehension for Security Risk Assessment: An Empirical Comparison of Tabular vs. Graphical Representations

作者: Katsiaryna Labunets , Flavio Moreira de Oliveira , Sabrina Marczak , Federica Paci , Fabio Massacci

DOI:

关键词:

摘要: Context: Tabular and graphical representations are used to communicate security risk assessments for IT systems. However, there is no consensus on which type of representation better supports the comprehension risks (such as relationships between threats, vulnerabilities controls). Vessey's cognitive fit theory predicts that graphs should be because they capture spatial relationships. Method: We report results two studies performed in countries with 69 83 participants respectively, we assessed effectiveness tabular concerning extraction correct information about risks. Results: Participants who applied models gave more precise complete answers questions when requested find simple complex vulnerabilities, or other elements models. Conclusions: Our findings can explained by implicitly elementary linear Interest ICSE: It almost taken granted Software Engineering graphical-, diagram-based "the" way go (e.g., SE Body Knowledge). This paper provides some experimental-based doubts this might not always case. will provide an interesting debate ripple traditional requirements design notations outside security.

参考文章(3)
Katsiaryna Labunets, Fabio Massacci, Alessandra Tedeschi, Graphical vs. tabular notations for risk models: on the role of textual labels and complexity empirical software engineering and measurement. pp. 267- 276 ,(2017) , 10.1109/ESEM.2017.40
Katsiaryna Labunets, Fabio Massacci, Federica Paci, Sabrina Marczak, Flávio Moreira de Oliveira, Model comprehension for security risk assessment: an empirical comparison of tabular vs. graphical representations Empirical Software Engineering. ,vol. 22, pp. 3017- 3056 ,(2017) , 10.1007/S10664-017-9502-8
Robert E Wood, Task complexity: Definition of the construct Organizational Behavior and Human Decision Processes. ,vol. 37, pp. 60- 82 ,(1986) , 10.1016/0749-5978(86)90044-0