{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T15:03:43Z","timestamp":1781103823272,"version":"3.54.1"},"reference-count":38,"publisher":"IGI Global Scientific Publishing","issue":"1","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2012,1,1]]},"abstract":"<p>A number of security mechanisms are available for improving the security of systems by restricting the actions of individual programs to activities that are authorised. However, configuring these systems to enforce end users\u2019 own security goals is often beyond their expertise. Little research has investigated the usability issues associated with application-oriented access controls. This paper presents the results of a qualitative analysis of user perceptions of the usability of three application-oriented security systems: SELinux, AppArmor, and FBAC-LSM. Qualitative analysis identified a number of factors that affect the usability of application-restriction mechanisms. These themes are used to compare the usability of the three systems studied, and it is proposed that these factors can be used to inform the design of new systems and development of existing ones. Changes to the three security systems are also proposed to address or mitigate specific usability issues that were identified.<\/p>","DOI":"10.4018\/jisp.2012010104","type":"journal-article","created":{"date-parts":[[2012,2,29]],"date-time":"2012-02-29T15:49:13Z","timestamp":1330530553000},"page":"57-76","source":"Crossref","is-referenced-by-count":7,"title":["Towards Usable Application-Oriented Access Controls"],"prefix":"10.4018","volume":"6","author":[{"given":"Z. Cliffe","family":"Schreuders","sequence":"first","affiliation":[{"name":"Leeds Metropolitan University, UK"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tanya","family":"McGill","sequence":"additional","affiliation":[{"name":"Murdoch University, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"Payne","sequence":"additional","affiliation":[{"name":"Murdoch University, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"2432","reference":[{"key":"jisp.2012010104-0","unstructured":"Alexander, J. D., & Jasna, K. (2006). Aligning usability and security: A usability study of Polaris. In Proceedings of the Second Symposium on Usable Privacy and Security, Pittsburgh, PA (pp. 1-7). New York, NY: ACM."},{"key":"jisp.2012010104-1","unstructured":"Alma, W., & Tygar, J. D. (1999). Why Johnny can't encrypt: A usability evaluation of PGP 5.0. In Proceedings of the 8th Conference on USENIX Security Symposium, Washington, DC (pp. 169-184). Berkeley, CA: USENIX."},{"key":"jisp.2012010104-2","unstructured":"Berman, A., Bourassa, V., & Selberg, E. (1995). TRON: Process-specific file protection for the UNIX operating system. In Proceedings of the Winter USENIX Conference, New Orleans, LA (pp. 165-175). Berkeley, CA: USENIX."},{"key":"jisp.2012010104-3","doi-asserted-by":"crossref","unstructured":"Brodie, C. A., Karat, C.-M., & Karat, J. (2006). An empirical study of natural language parsing of privacy policy rules using the SPARCLE Policy Workbench. In Proceedings of the 2nd Symposium on Usable Privacy and Security, Pittsburgh, PA (pp. 8-19). New York, NY: ACM.","DOI":"10.1145\/1143120.1143123"},{"key":"jisp.2012010104-4","first-page":"189","article-title":"SUS: A quick and dirty usability scale","author":"J.Brooke","year":"1996","journal-title":"Usability evaluation in industry"},{"key":"jisp.2012010104-5","doi-asserted-by":"crossref","unstructured":"Cao, X., & Iverson, L. (2006). Intentional access management: Making access control usable for end-users. In Proceedings of the 2nd Symposium on Usable Privacy and Security, Pittsburgh, PA (pp. 20-31). New York, NY: ACM.","DOI":"10.1145\/1143120.1143124"},{"key":"jisp.2012010104-6","unstructured":"Cowan, C., Beattie, S., Kroah-Hartman, G., Pu, C., Wagle, P., & Gligor, V. (2000). SubDomain: Parsimonious server security. In Proceedings of the USENIX 14th Systems Administration Conference, New Orleans, LA. Berkeley, CA: USENIX."},{"key":"jisp.2012010104-7","author":"L.Cranor","year":"2005","journal-title":"Security and usability: Designing secure systems that people can use"},{"key":"jisp.2012010104-8","doi-asserted-by":"crossref","unstructured":"DeWitt, A. J., & Kuljis, J. (2006). Aligning usability and security: A usability study of Polaris. In Proceedings of the 2nd Symposium on Usable Privacy and Security, Pittsburgh, PA (pp. 1-7). New York, NY: ACM.","DOI":"10.1145\/1143120.1143122"},{"key":"jisp.2012010104-9","author":"R.Dhamankar","year":"2009","journal-title":"The top cyber security risks (Tech. Rep.)"},{"key":"jisp.2012010104-10","unstructured":"Goldberg, I., Wagner, D., Thomas, R., & Brewer, E. A. (1996). A secure environment for untrusted helper applications: Confining the wily hacker. In Proceedings of the 6th USENIX Security Symposium, San Jose, CA (p. 1). Berkeley, CA: USENIX."},{"key":"jisp.2012010104-11","unstructured":"Hallyn, S. E., & Kearns, P. (2000). Domain and type enforcement for Linux. In Proceedings of the 4th Annual Linux Showcase and Conference, Atlanta, GA (pp. 247-260). Berkeley, CA: USENIX."},{"key":"jisp.2012010104-12","unstructured":"Harada, T., Horie, T., & Tanaka, K. (2004). Task oriented management obviates your onus on Linux. In Proceedings of the Linux Conference, Tokyo, Japan."},{"key":"jisp.2012010104-13","doi-asserted-by":"publisher","DOI":"10.1016\/0167-4048(95)97088-R"},{"key":"jisp.2012010104-14","doi-asserted-by":"crossref","unstructured":"Johnson, M., Karat, J., Karat, C.-M., & Grueneberg, K. (2010a). Optimizing a policy authoring framework for security and privacy policies. In Proceedings of the 6th Symposium on Usable Privacy and Security, Washington, DC (p. 8). New York, NY: ACM.","DOI":"10.1145\/1837110.1837121"},{"key":"jisp.2012010104-15","doi-asserted-by":"crossref","unstructured":"Johnson, M., Karat, J., Karat, C. M., & Grueneberg, K. (2010b). Usable policy template authoring for iterative policy refinement. In Proceedings of the IEEE International Symposium on Policies for Distributed Systems and Networks, Fairfax, VA (pp. 18-21). Washington, DC: IEEE Computer Society.","DOI":"10.1109\/POLICY.2010.28"},{"key":"jisp.2012010104-16","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2005.04.011"},{"key":"jisp.2012010104-17","doi-asserted-by":"crossref","unstructured":"Motiee, S., Hawkey, K., & Beznosov, K. (2010). Do Windows users follow the principle of least privilege? Investigating user account control practices. In Proceedings of the 6th Symposium on Usable Privacy and Security, Washington, DC (p. 1). New York, NY: ACM.","DOI":"10.1145\/1837110.1837112"},{"key":"jisp.2012010104-18","unstructured":"Nakamura, Y., Sameshima, Y., & Tabata, T. (2009). SEEdit: SELinux security policy configuration system with higher level language. In Proceedings of the 23rd Large Installation System Administration Conference, Baltimore, MD (pp. 107-117). Berkeley, CA: USENIX."},{"key":"jisp.2012010104-19","unstructured":"Ott, A. (2002). The role compatibility security model. In Proceedings of the 7th Nordic Workshop on Secure IT Systems, Karlstad, V\u00e4rmland, Sweden."},{"key":"jisp.2012010104-20","unstructured":"Potter, S., & Nieh, J. (2010). Apiary: Easy-to-use desktop application fault containment on commodity operating systems. In Proceedings of the USENIX Annual Technical Conference, Boston, MA (p. 8). Berkeley, CA: USENIX."},{"key":"jisp.2012010104-21","unstructured":"Provos, N. (2002). Improving host security with system call policies. In Proceedings of the 12th USENIX Security Symposium, Washington, DC (p. 18). Berkley, CA: USENIX."},{"key":"jisp.2012010104-22","doi-asserted-by":"crossref","unstructured":"Reeder, R. W., Bauer, L., Cranor, L. F., Reiter, M. K., Bacon, K., How, K., et al. (2008). Expandable grids for visualizing and authoring computer security policies. In Proceedings of the 26th Annual SIGCHI Conference on Human Factors in Computing Systems, Florence, Italy (pp. 1473-1482). New York, NY: ACM.","DOI":"10.1145\/1357054.1357285"},{"key":"jisp.2012010104-23","doi-asserted-by":"crossref","unstructured":"Reeder, R. W., Karat, C.-M., Karat, J., & Brodie, C. (2007). Usability challenges in security and privacy policy-authoring Interfaces. In C. Baranauskas, P. Palanque, J. Abascal, & S. D. J. Barbosa (Eds.), Proceedings of the 11th IFIP TC 13 International Conference on Human-computer Interaction, Rio de Janeiro, Brazil (LNCS 4663, pp. 141-155).","DOI":"10.1007\/978-3-540-74800-7_11"},{"key":"jisp.2012010104-24","doi-asserted-by":"publisher","DOI":"10.1177\/1525822X02239569"},{"key":"jisp.2012010104-25","doi-asserted-by":"publisher","DOI":"10.1109\/PROC.1975.9939"},{"key":"jisp.2012010104-26","unstructured":"Schaufler, C. (2008). The simplified mandatory access control kernel. Retrieved from http:\/\/people.xiph.org\/~giles\/2008\/lca\/mirror\/...\/092-SmackLCA2007.ppt"},{"key":"jisp.2012010104-27","unstructured":"Schmid, M., Hill, F., & Ghosh, A. K. (2002). Protecting data from malicious software. In Proceedings of the 18th Annual Computer Security Applications Conference (pp. 199-208). Washington, DC: IEEE Computer Society."},{"key":"jisp.2012010104-28","doi-asserted-by":"publisher","DOI":"10.1145\/2019599.2019604"},{"key":"jisp.2012010104-29","doi-asserted-by":"crossref","unstructured":"Schreuders, Z. C., & Payne, C. (2008a). Functionality-based application confinement: Parameterised hierarchical application restrictions. In Proceedings of the International Conference on Security and Cryptography, Porto, Portugal (pp. 72-77). Setubal, Portugal: INSTICC.","DOI":"10.5220\/0001928900720077"},{"key":"jisp.2012010104-30","doi-asserted-by":"crossref","unstructured":"Schreuders, Z. C., & Payne, C. (2008b). Reusability of functionality-based application confinement policy abstractions. In Proceedings of the 10th International Conference on Information and Communications Security, Birmingham, UK (pp. 206-221).","DOI":"10.1007\/978-3-540-88625-9_14"},{"key":"jisp.2012010104-31","doi-asserted-by":"crossref","unstructured":"Schreuders, Z. C., Payne, C., & McGill, T. (2011). Techniques for automating policy specification for application-oriented access controls. In Proceedings of the 6th International Conference on Availability, Reliability and Security, Vienna, Austria. Washington, DC: IEEE Computer Society.","DOI":"10.1109\/ARES.2011.47"},{"key":"jisp.2012010104-32","unstructured":"Smalley, S., Vance, C., & Salamon, W. (2001). Implementing SELinux as a Linux Security Module (Tech. Rep. No. NAI Labs Report #01-043). Washington, DC: National Security Agency (NSA)."},{"key":"jisp.2012010104-33","doi-asserted-by":"publisher","DOI":"10.1145\/1151030.1151033"},{"key":"jisp.2012010104-34","unstructured":"Suse. (2011). AppArmor and SELinux comparison. Retrieved from http:\/\/www.novell.com\/linux\/security\/apparmor\/selinux_comparison.html"},{"key":"jisp.2012010104-35","unstructured":"Wright, C., Cowan, C., Smalley, S., Morris, J., & Kroah-Hartman, G. (2002). Linux security module framework. In Proceedings of the Ottawa Linux Symposium, Ottawa, ON, Canada."},{"key":"jisp.2012010104-36","unstructured":"Zurko, M. E., Simon, R., & Sanfilippo, T. (1999). A user-centered, modular authorization service built on an RBAC foundation. In Proceedings of the IEEE Symposium on Security and Privacy (pp. 57-71). Washington, DC: IEEE Computer Society. Z."},{"key":"jisp.2012010104-37","doi-asserted-by":"crossref","unstructured":"Zurko, M. E., & Simon, R. T. (1996). User-centered security. In Proceedings of the New Security Paradigms Workshop, Lake Arrowhead, CA (pp. 27-33). New York, NY: ACM.","DOI":"10.1145\/304851.304859"}],"container-title":["International Journal of Information Security and Privacy"],"original-title":[],"language":"ng","link":[{"URL":"https:\/\/www.igi-global.com\/viewtitle.aspx?TitleId=64346","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,22]],"date-time":"2025-03-22T02:44:07Z","timestamp":1742611447000},"score":1,"resource":{"primary":{"URL":"https:\/\/services.igi-global.com\/resolvedoi\/resolve.aspx?doi=10.4018\/jisp.2012010104"}},"subtitle":["Qualitative Results from a Usability Study of SELinux, AppArmor and FBAC-LSM"],"short-title":[],"issued":{"date-parts":[[2012,1,1]]},"references-count":38,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2012,1]]}},"URL":"https:\/\/doi.org\/10.4018\/jisp.2012010104","relation":{},"ISSN":["1930-1650","1930-1669"],"issn-type":[{"value":"1930-1650","type":"print"},{"value":"1930-1669","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,1,1]]}}}