To main content

An Empirical Study on the Comprehensibility of Graphical Security Risk Models Based on Sequence Diagrams

Abstract

We report on an empirical study in which we evaluate the comprehensibility of graphical versus textual risk annotations in threat models based on sequence diagrams. The experiment was carried out on two separate groups where each group solved tasks related to either graphical or textual annotations. We also examined the efficiency of using these two annotations in terms of the average time each group spent per task. Our study reports that threat models with textual risk annotations are equally comprehensible to corresponding threat models with graphical risk annotations. With respect to efficiency, however, we found out that participants solving tasks related to the graphical annotations spent on average 23% less time per task.
Read publication

Category

Academic article

Client

  • Research Council of Norway (RCN) / 236657

Language

English

Author(s)

Affiliation

  • SINTEF Digital / Sustainable Communication Technologies

Year

2019

Published in

Lecture Notes in Computer Science (LNCS)

ISSN

0302-9743

Publisher

Springer

Volume

11391

Page(s)

1 - 17

View this publication at Cristin