System End-User Actions as a Threat to Information System Security

Paulus Kautwima, Titus Haiduwa, K. Sai, V. Hashiyana, N. Suresh
{"title":"System End-User Actions as a Threat to Information System Security","authors":"Paulus Kautwima, Titus Haiduwa, K. Sai, V. Hashiyana, N. Suresh","doi":"10.5121/ijnsa.2021.13606","DOIUrl":null,"url":null,"abstract":"As universities migrate online due to the advent of Covid-19, there is a need for enhanced security in information systems in the institution of higher learning. Many opted to invest in technological approaches to mitigate cybersecurity threats; however, the most common types of cybersecurity breaches happen due to the human factor, well known as end-user error or actions. Thus, this study aimed to identify and explore possible end-user errors in academia and the resulting vulnerabilities and threats that could affect the integrity of the university's information system. The study further presented state-of-the-art humanoriented security threats countermeasures to compliment universities' cybersecurity plans. Countermeasures include well-tailored ICT policies, incident response procedures, and education to protect themselves from security events (disruption, distortion, and exploitation). Adopted is a mixedmethod research approach with a qualitative research design to guide the study. An open-ended questionnaire and semi-structured interviews were used as data collection tools. Findings showed that system end-user errors remain the biggest security threat to information systems security in institutions of higher learning. Indeed errors make information systems vulnerable to certain cybersecurity attacks and, when exploited, put legitimate users, institutional network, and its computers at risk of contracting viruses, worms, Trojan, and expose it to spam, phishing, e-mail fraud, and other modern security attacks such as DDoS, session hijacking, replay attack and many more. Understanding that technology has failed to fully protect systems, specific recommendations are provided for the institution of higher education to consider improving employee actions and minimizing security incidents in their eLearning platforms, post Covid-19.","PeriodicalId":93303,"journal":{"name":"International journal of network security & its applications","volume":"69 1","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2021-11-30","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"International journal of network security & its applications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.5121/ijnsa.2021.13606","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

As universities migrate online due to the advent of Covid-19, there is a need for enhanced security in information systems in the institution of higher learning. Many opted to invest in technological approaches to mitigate cybersecurity threats; however, the most common types of cybersecurity breaches happen due to the human factor, well known as end-user error or actions. Thus, this study aimed to identify and explore possible end-user errors in academia and the resulting vulnerabilities and threats that could affect the integrity of the university's information system. The study further presented state-of-the-art humanoriented security threats countermeasures to compliment universities' cybersecurity plans. Countermeasures include well-tailored ICT policies, incident response procedures, and education to protect themselves from security events (disruption, distortion, and exploitation). Adopted is a mixedmethod research approach with a qualitative research design to guide the study. An open-ended questionnaire and semi-structured interviews were used as data collection tools. Findings showed that system end-user errors remain the biggest security threat to information systems security in institutions of higher learning. Indeed errors make information systems vulnerable to certain cybersecurity attacks and, when exploited, put legitimate users, institutional network, and its computers at risk of contracting viruses, worms, Trojan, and expose it to spam, phishing, e-mail fraud, and other modern security attacks such as DDoS, session hijacking, replay attack and many more. Understanding that technology has failed to fully protect systems, specific recommendations are provided for the institution of higher education to consider improving employee actions and minimizing security incidents in their eLearning platforms, post Covid-19.
系统终端用户行为对信息系统安全的威胁
由于新冠肺炎疫情的到来,大学纷纷转向网络,因此需要加强高等院校信息系统的安全性。许多企业选择投资技术手段来缓解网络安全威胁;然而,最常见的网络安全漏洞类型是由于人为因素造成的,即最终用户错误或操作。因此,本研究旨在识别和探索学术界可能出现的最终用户错误,以及由此产生的可能影响大学信息系统完整性的漏洞和威胁。该研究进一步提出了最先进的以人为本的安全威胁对策,以配合大学的网络安全计划。对策包括量身定制的ICT政策、事件响应程序和教育,以保护自己免受安全事件(中断、扭曲和利用)的影响。采用混合方法研究方法,采用定性研究设计来指导研究。采用开放式问卷和半结构化访谈作为数据收集工具。调查结果显示,系统终端用户错误仍然是高校信息系统安全的最大安全威胁。事实上,错误使信息系统容易受到某些网络安全攻击,一旦被利用,就会使合法用户、机构网络及其计算机面临感染病毒、蠕虫、木马的风险,并使其暴露于垃圾邮件、网络钓鱼、电子邮件欺诈和其他现代安全攻击,如DDoS、会话劫持、重放攻击等等。了解到技术无法完全保护系统,本文为高等教育机构提供了具体建议,以考虑在2019冠状病毒病后改善员工行为并最大限度地减少其电子学习平台中的安全事件。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信