MORPHEUS: A Multidimensional Framework for Modeling, Measuring, and Mitigating Human Factors in Cybersecurity

📅 2025-12-20
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Human factors in cybersecurity remain conceptualized as static, isolated vulnerabilities, lacking systematic modeling and empirical validation. Method: This paper introduces the first dynamic, multidimensional human-factor cybersecurity framework, integrating a cognitive-affective-behavioral model with attribution theory to systematically identify 50 human factors and 295 interaction mechanisms, and to formally define 12 types of human-factor interactions. Leveraging systematic mapping analysis and empirical psychometrics, we develop a psychometric toolkit comprising 99 actionable metrics. Contribution/Results: The framework enables a paradigm shift from static trait-based perspectives to dynamic systems thinking. It yields three applied outputs: (1) a human-risk diagnostic protocol, (2) evidence-based security training guidelines, and (3) human-centered interface design principles. This work establishes a unified theoretical foundation and engineering-ready infrastructure for human-centric cybersecurity research and practice.

Technology Category

Application Category

📝 Abstract
Current cybersecurity research increasingly acknowledges the human factor, yet remains fragmented, often treating user vulnerabilities as isolated and static traits. This paper introduces MORPHEUS, a holistic framework that operationalizes human-centric security as a dynamic and interconnected system. Grounded in the Cognition-Affect-Behavior (CAB) model and Attribution Theory, MORPHEUS consolidates 50 human factors influencing susceptibility to major cyberthreats, including phishing, malware, password management, and misconfigurations. Beyond factor identification, the framework systematically maps 295 documented interactions, revealing how cognitive, emotional, behavioral, and socio-organizational processes jointly shape security outcomes, and distills them into twelve recurring interaction mechanisms. MORPHEUS further links theory to practice through an inventory of 99 validated psychometric instruments, enabling empirical assessment and targeted intervention. We illustrate the framework's applicability through concrete operational scenarios, spanning risk diagnosis, training, and interface design. Overall, MORPHEUS provides a rigorous yet actionable foundation for advancing human-centered cybersecurity research and practice.
Problem

Research questions and friction points this paper is trying to address.

Integrates human factors into cybersecurity as a dynamic, interconnected system.
Identifies and maps interactions among cognitive, emotional, and behavioral factors influencing cyberthreat susceptibility.
Provides tools for empirical assessment and targeted interventions in human-centered cybersecurity.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Integrates 50 human factors into a dynamic, interconnected system
Maps 295 interactions using cognitive, emotional, behavioral mechanisms
Links theory to practice with 99 validated psychometric instruments
🔎 Similar Papers
No similar papers found.
Giuseppe Desolda
Giuseppe Desolda
University of Bari Aldo Moro
Novel Interaction TechniquesInternet of ThingsUsable Security
F
Francesco Greco
Department of Computer Science, University of Bari, Italy
Rosa Lanzilotti
Rosa Lanzilotti
University of Bari
Usability Engineering and UX
C
Cesare Tucci
Department of Computer Science, University of Bari, Italy