论文标题
仔细观察用于分析安全建议集的系统方法
A Close Look at a Systematic Method for Analyzing Sets of Security Advice
论文作者
论文摘要
我们对Barrera等人的安全咨询编码方法(SACODING)进行了详细分析。 (2021),旨在分析安全建议,以衡量可行性和将建议项目分类为实践,政策,原理或结果。我们的分析的主要部分探讨了第二个编码人员将代码分配给建议项目的代码分配的程度,该代码与第一个编码的分配,对于1013个安全建议项目的数据集,名义上介绍了物联网设备。更广泛地说,我们寻求更深入地了解糖座方法的健全性和效用,以及它符合设计目标的程度,即在将代码分配给安全建议项目时降低主观性。我们的分析导致建议修改编码树方法以及一些建议。我们认为,编码树方法可能仅仅是仅安全建议数据集的定性数据分析。
We carry out a detailed analysis of the security advice coding method (SAcoding) of Barrera et al. (2021), which is designed to analyze security advice in the sense of measuring actionability and categorizing advice items as practices, policies, principles, or outcomes. The main part of our analysis explores the extent to which a second coder's assignment of codes to advice items agrees with that of a first, for a dataset of 1013 security advice items nominally addressing Internet of Things devices. More broadly, we seek a deeper understanding of the soundness and utility of the SAcoding method, and the degree to which it meets the design goal of reducing subjectivity in assigning codes to security advice items. Our analysis results in suggestions for modifications to the coding tree methodology, and some recommendations. We believe the coding tree approach may be of interest for analysis of qualitative data beyond security advice datasets alone.