Decision-making plays a crucial role in information security. Understanding how cognitive biases affect the decision-making process is important in identifying biases and implementing mitigations to improve the quality of decisions. Previous research in aspects of security and usability has examined how users’ misunderstandings of security protocols may be due to various forms of bias. This paper focuses on cognitive bias in security decision-making and its substantial impact on new technologies such as artificial intelligence and machine learning. To examine the gap, this research conducts a systematic review of previous relevant studies and develops hypotheses based on empirical analysis to understand biases that affect the efficiency of security decision-making with a specific focus on AI/ML-based security systems. A comprehensive framework to help mitigate the detrimental effects of these biases on security decision quality includes the use of debiasing algorithms, decision support systems, and hybrid decision-making.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Understanding Cognitive Biases in Security Decision-Making and Proposing Effective Mitigation Strategies

  • Elizabeth Mansaray,
  • Mohamed Abdulnabi,
  • Yogeswaran Nathan,
  • Shahab Alizadeh,
  • Aitizaz Ali,
  • A. L.-Anood AL-Maari,
  • Waheed Ali H. M. Ghanem

摘要

Decision-making plays a crucial role in information security. Understanding how cognitive biases affect the decision-making process is important in identifying biases and implementing mitigations to improve the quality of decisions. Previous research in aspects of security and usability has examined how users’ misunderstandings of security protocols may be due to various forms of bias. This paper focuses on cognitive bias in security decision-making and its substantial impact on new technologies such as artificial intelligence and machine learning. To examine the gap, this research conducts a systematic review of previous relevant studies and develops hypotheses based on empirical analysis to understand biases that affect the efficiency of security decision-making with a specific focus on AI/ML-based security systems. A comprehensive framework to help mitigate the detrimental effects of these biases on security decision quality includes the use of debiasing algorithms, decision support systems, and hybrid decision-making.