Exploiting predictability in click-based graphical passwords

被引:37
|
作者
van Oorschot, P. [1 ]
Thorpe, Julie [2 ]
机构
[1] Carleton Univ, Sch Comp Sci, Ottawa, ON, Canada
[2] Univ Ontario Inst Technol, Fac Business & Informat Technol, Oshawa, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Graphical passwords; PassPoints; passwords; hot spots; human-seeded attacks; human computation; click-order patterns; password guessing; dictionary attack; empirical studies; user choice;
D O I
10.3233/JCS-2010-0411
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We provide an in-depth study of the security of click-based graphical password schemes like PassPoints (Weidenbeck et al., 2005), by exploring popular points (hot-spots), and examining strategies to predict and exploit them in guessing attacks. We report on both short-and long-term user studies: one lab-controlled, involving 43 users and 17 diverse images, the other a field test of 223 user accounts. We provide empirical evidence that hot-spots do exist for many images, some more so than others. We explore the use of "human-computation" (in this context, harvesting click-points from a small set of users) to predict these hot-spots. We generate two "human-seeded" attacks based on this method: one based on a first-order Markov model, another based on an independent probability model. Within 100 guesses, our first-order Markov model-based attack finds 4% of passwords in one image's data set, and 10% of passwords in a second image's data set. Our independent model-based attack finds 20% within 2(33) guesses in one image's data set and 36% within 2(31) guesses in a second image's data set. These are all for a system whose full password space has cardinality 2(43). We evaluate our first-order Markov model-based attack with cross-validation of the field study data, which finds an average of 7-10% of user passwords within 3 guesses. We also begin to explore some click-order pattern attacks, which we found improve on our independent model-based attacks. Our results suggest that these graphical password schemes (with parameters as originally proposed) are vulnerable to offline and online attacks, even on systems that implement conservative lock-out policies.
引用
收藏
页码:669 / 702
页数:34
相关论文
共 50 条
  • [1] On Purely Automated Attacks and Click-Based Graphical Passwords
    Salehi-Abari, Amirali
    Thorpe, Julie
    van Oorschot, P. C.
    [J]. 24TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2008, : 111 - 120
  • [2] Guessing Click-Based Graphical Passwords by Eye Tracking
    LeBlanc, Daniel
    Forget, Alain
    Biddle, Robert
    [J]. PST 2010: 2010 EIGHTH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST, 2010, : 197 - 204
  • [3] Multiple Password Interference in Text Passwords and Click-Based Graphical Passwords
    Chiasson, Sonia
    Forget, Alain
    Stobert, Elizabeth
    van Oorschot, P. C.
    Biddle, Robert
    [J]. CCS'09: PROCEEDINGS OF THE 16TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2009, : 500 - 511
  • [4] Exploring Usability Effects of Increasing Security in Click-based Graphical Passwords
    Stobert, Elizabeth
    Forget, Alain
    Chiasson, Sonia
    van Oorschot, P. C.
    Biddle, Robert
    [J]. 26TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE (ACSAC 2010), 2010, : 79 - 88
  • [5] User interface design affects security: patterns in click-based graphical passwords
    Sonia Chiasson
    Alain Forget
    Robert Biddle
    P. C. van Oorschot
    [J]. International Journal of Information Security, 2009, 8 : 387 - 398
  • [6] User interface design affects security: patterns in click-based graphical passwords
    Chiasson, Sonia
    Forget, Alain
    Biddle, Robert
    van Oorschot, P. C.
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2009, 8 (06) : 387 - 398
  • [7] Security Analyses of Click-based Graphical Passwords via Image Point Memorability
    Zhu, Bin B.
    Yan, Jeff
    Wei, Dongchen
    Yang, Maowei
    [J]. CCS'14: PROCEEDINGS OF THE 21ST ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2014, : 1217 - 1231
  • [8] The Impact of Image Choices on the Usability and Security of Click Based Graphical Passwords
    Suo, Xiaoyuan
    Zhu, Ying
    Owen, G. Scott
    [J]. ADVANCES IN VISUAL COMPUTING, PT 2, PROCEEDINGS, 2009, 5876 : 889 - +
  • [9] Click to Enter: Comparing Graphical and Textual Passwords for Children
    Cole, Jasper
    Walsh, Greg
    Pease, Zachary
    [J]. PROCEEDINGS OF THE 2017 ACM CONFERENCE ON INTERACTION DESIGN AND CHILDREN (IDC 2017), 2017, : 472 - 477
  • [10] CPot: Click-based honeypot
    Li, Weimin
    Shu, Kejin
    Zhu, Xiaodong
    [J]. Qinghua Daxue Xuebao/Journal of Tsinghua University, 2010, 50 (SUPPL. 1): : 1566 - 1571