Augmenting Digital Ecosystem Resilience Through Human-Centric Cybersecurity Solutions
本文提出一种结合多源数据和分类方法的系统,通过考虑用户行为和心理因素来提升数字生态系统的网络安全韧性,实验显示性能提升11%,用户满意度提高15%。
As more of our personal, social, and economic activities move online, the systems that support them, known as digital ecosystems, are becoming increasingly complex and vulnerable to cyberattacks. While many cybersecurity solutions focus on technical threats, they often overlook the human element, which remains a critical weakness. People's perceptions, behaviours, and decisions can significantly impact the security of these systems, but current approaches rarely take these factors into account. This paper addresses this gap by proposing a system that interprets human-related cybersecurity data in context. The system uses a combination of multiple types of data (such as user activity logs and behavioural indicators) and a structured classification method to better understand and respond to user-related risks. We also introduce a reference model that blends zero-trust security (which assumes no user or device is trusted by default) with a flexible trust framework that adapts to individual user needs. To evaluate the effectiveness of our approach, we compare it against established machine learning techniques, such as support vector machines (which identify boundaries between data groups) and random forests (which utilise decision rules to classify data), using a publicly available dataset that simulates both normal and malicious computer activity. We also assess how well the system performs when reducing data complexity and report standard performance metrics, such as precision (the percentage of flagged risks that are correct), recall (the percentage of real risks that are detected), and F1-score (a balance between precision and recall). Our results show an 11% improvement over the benchmarks. Beyond technical performance, we further evaluated the system through a user study. Participants responded to both rating-scale questions and open-ended questions. The numerical responses provided us with measurable insights into user satisfaction and the ease of use of the system. We also analysed the written comments to understand whether users had positive, neutral, or adverse reactions. By combining these types of feedback, we found that agreement with user-friendly security practices increased by 15%, indicating growing support for approaches that better align with how people actually use and experience cybersecurity tools.