Høgskolen i Gjøvik

HiG / IMT / emnesider / IMT4901 / recent / is2008 / thesis2008 / Risa, Terje

Risa, Terje

Risa, TerjeZero effort security for the home PC users?

Presentation

Introduction

With the increasing use of Internet to access sensitive information, online banking and electronic commerce, is the need for proper protection of home computers a pressing issue. Home computers are becoming a more valuable and easier target for malicious users than corporate computers, and thus increasing the threat against home PCs. The service providers ensure adequate protection for their services, but not for the computer accessing these services. Some service providers like for instance online banking gives out computer security software, like anti-virus programs to their customers, but very often is the user left alone to properly protect the computer. For the service providers to be able too recommend different solutions suited for the home computer users, is there a need for showing how good these solutions are with emphasis on usability.

Problem description

Security in online banking systems and information portals containing sensitive user information has been a very important subject. This has resulted in more secure solutions for the users, for instance the use of one-time password in conjunction with online banking. This focus on improving the security of corporations and businesses, has lead to security threat shifting toward including attacks against home computer also. Since corporate computers have become more difficult to attack, together with the propagation of home computer connecting to the Internet with broadband connection, has home computers become a more valuable target for malicious attacks.

Unfortunately is often the home PC security neglected when for instance securing an information portal or online bank, even though many users use these computers when accessing the sensitive information. Some online banking companies provide the users with anti-virus software, but this does not ensure that the user is protected enough. To improve on the problem of home computers being contaminated with malware and becoming part of bot-nets, user's needs user-friendly security solutions approved by the service providers. It is particularly important that the security solutions are usable for the common home computer user, for it to be used.

Justification, motivation and benefits

With the increasing use of sensitive information accessed via home computers, the service providers need to continually improve the security and defense of their product. One important step in the direction of getting satisfactory protection is not only to secure the service provided, but also help to secure the end-users. This would greatly increase the total security, and would help the users from getting their sensitive information leaked to potential attackers.

Research questions

  • Which vulnerabilities and threats are of current interest?
  • What security products/solutions are available for common home computer users?
  • How can you measure security products effectiveness?
  • How good protection can the identified products give?
  • What effort is needed to install, maintain and use the different products?

Planned contributions

Hopefully this project will give service providers the ability to see the relations between effect and user-friendliness for some different security solutions. Based on this it can be easier to recommend which security solutions that are most fitted for the common home computer user. In the course of this MSc project, will the trade-offs between required effort and security effectiveness (how good protection it can provide) for some security solutions specifically made for home computers be visualized.

17.03.2009