Security Implications of User Non-compliance Behavior to Software Updates: A Risk Assessment Study
Mahzabin Tamanna, Mohd Anwar, Joseph D.W. Stephens

TL;DR
This study investigates how psychological factors and risk information influence user compliance with software updates, proposing a risk assessment model and demonstrating that targeted information can increase update willingness.
Contribution
The paper introduces a model using NVD attributes to assess update delay risks and shows that providing risk scores and vulnerability info enhances user update behavior.
Findings
Providing risk scores increases update willingness
No significant gender difference in update behavior
Risk communication can improve system security
Abstract
Software updates are essential to enhance security, fix bugs, and add better features to the existing software. While some users accept software updates, non-compliance remains a widespread issue. While some users accept software updates, non-compliance remains a widespread issue. End users' systems remain vulnerable to security threats when security updates are not installed or are installed with a delay. Despite research efforts, users' noncompliance behavior with software updates is still prevalent. In this study, we explored how psychological factors influence users' perception and behavior toward software updates. In addition, we investigated how information about potential vulnerabilities and risk scores influences their behavior. Next, we proposed a model that utilizes attributes from the National Vulnerability Database (NVD) to effectively assess the overall risk score…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsInformation and Cyber Security · Advanced Malware Detection Techniques
