Standing out among the daily spam: How to catch website owners' attention by means of vulnerability notifications

Hennig, Anne ORCID iD icon 1; Neusser, Fabian; Pawelek, Aleksandra Alicja 1; Herrmann, Dominik; Mayer, Peter ORCID iD icon 1
1 Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB), Karlsruher Institut für Technologie (KIT)


Running a business without having a website is nearly impossible nowadays. Most business owners use content managements sys- tems to manage their websites. Yet, those can pose security risks and provide vulnerabilities for manipulations. With vulnerability notifications, website owners are notified about security risks. To identify common themes with respect to vulnerability notifications and provide deeper insight into the motivations of website owners to react to those notifications, we conducted 25 semi-structured interviews. In compliance with previous research, we could confirm that distrust in unexpected notifications is high and, in contrast to previous research, we suggest that verification possibilities are the most important factors to establish trust in notifications. We also endorse the findings that raising awareness for the severity and the complexity of the problems is crucial to increase remediation rates.

DOI: 10.5445/IR/1000144116
Veröffentlicht am 23.05.2022
DOI: 10.1145/3491101.3519847
Zitationen: 1
Zugehörige Institution(en) am KIT Institut für Angewandte Informatik und Formale Beschreibungsverfahren (AIFB)
Publikationstyp Proceedingsbeitrag
Publikationsjahr 2022
Sprache Englisch
Identifikator ISBN: 978-1-4503-9156-6
KITopen-ID: 1000144116
HGF-Programm 46.23.01 (POF IV, LK 01) Methods for Engineering Secure Systems
Erschienen in Conference on Human Factors in Computing Systems (CHI ’22) : Extended Abstracts
Veranstaltung Conference on Human Factors in Computing Systems (CHI 2022), New Orleans, LA, USA, 30.04.2022 – 06.05.2022
Verlag Association for Computing Machinery (ACM)
Seiten Art.-Nr.: 317
Projektinformation INSPECTION (BMBF, 16KIS1113)
Nachgewiesen in Dimensions
