We undertake a comprehensive and structured synthesis of the drivers of human behavior in cybersecurity, focusing specifically on people within organizations (i.e., especially employees in companies), and integrate key concepts such as awareness, security culture, and usability into a coherent theoretical framework. This model is then compared with several relevant behavioral models that fundamentally represent drivers of human behavior. Additionally, we discuss how this theoretical framework can help the domain of agentic AI security: We argue that as AI systems increasingly act as autonomous agents within organizations and based on natural language processing, they also exhibit vulnerabilities analogous to human behavioral risks. Consequently, we propose that this human-centric model offers a blueprint for developing additional security strategies against manipulation attacks targeting AI agents.
翻译:我们对网络安全中人类行为的驱动因素进行了全面且结构化的综合分析,特别聚焦于组织内人员(即企业员工),并将安全意识、安全文化及可用性等关键概念整合为一个连贯的理论框架。该模型随后与多个本质上表征人类行为驱动因素的相关行为模型进行了比较。此外,我们探讨了这一理论框架如何助力于代理型人工智能安全领域:我们认为,随着人工智能系统日益作为自主代理在组织内基于自然语言处理技术运作,它们同样会表现出类似于人类行为风险的脆弱性。因此,我们提出这一以人为中心的模型可为开发针对人工智能代理的操纵攻击的附加安全策略提供蓝图。