Exploiting predictability in click-based graphical passwords

被引:37
|
作者
van Oorschot, P. [1 ]
Thorpe, Julie [2 ]
机构
[1] Carleton Univ, Sch Comp Sci, Ottawa, ON, Canada
[2] Univ Ontario Inst Technol, Fac Business & Informat Technol, Oshawa, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Graphical passwords; PassPoints; passwords; hot spots; human-seeded attacks; human computation; click-order patterns; password guessing; dictionary attack; empirical studies; user choice;
D O I
10.3233/JCS-2010-0411
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
We provide an in-depth study of the security of click-based graphical password schemes like PassPoints (Weidenbeck et al., 2005), by exploring popular points (hot-spots), and examining strategies to predict and exploit them in guessing attacks. We report on both short-and long-term user studies: one lab-controlled, involving 43 users and 17 diverse images, the other a field test of 223 user accounts. We provide empirical evidence that hot-spots do exist for many images, some more so than others. We explore the use of "human-computation" (in this context, harvesting click-points from a small set of users) to predict these hot-spots. We generate two "human-seeded" attacks based on this method: one based on a first-order Markov model, another based on an independent probability model. Within 100 guesses, our first-order Markov model-based attack finds 4% of passwords in one image's data set, and 10% of passwords in a second image's data set. Our independent model-based attack finds 20% within 2(33) guesses in one image's data set and 36% within 2(31) guesses in a second image's data set. These are all for a system whose full password space has cardinality 2(43). We evaluate our first-order Markov model-based attack with cross-validation of the field study data, which finds an average of 7-10% of user passwords within 3 guesses. We also begin to explore some click-order pattern attacks, which we found improve on our independent model-based attacks. Our results suggest that these graphical password schemes (with parameters as originally proposed) are vulnerable to offline and online attacks, even on systems that implement conservative lock-out policies.
引用
收藏
页码:669 / 702
页数:34
相关论文
共 50 条
  • [41] Click-based evidence for decaying weight distributions in search effectiveness metrics
    Yuye Zhang
    Laurence A. F. Park
    Alistair Moffat
    [J]. Information Retrieval, 2010, 13 : 46 - 69
  • [42] Click-Based Representation Learning Framework of Student Navigational Behavior in MOOCs
    Al Amoudi, Shrooq
    Alhothali, Areej
    Mirza, Rsha
    Assalahi, Hussein
    Aldosemani, Tahani
    [J]. IEEE ACCESS, 2024, 12 : 121480 - 121494
  • [43] Functionalizing tandem mass tags for streamlining click-based quantitative chemoproteomics
    Burton, Nikolas R.
    Backus, Keriann M.
    [J]. COMMUNICATIONS CHEMISTRY, 2024, 7 (01)
  • [44] Evaluating Voxel-Based Graphical Passwords for Virtual Reality
    Rawat, Prashant
    Turkmen, Rumeysa
    Nwagu, Chukwuemeka
    Sunday, Kissinger
    Machuca, Mayra Donaji Barrera
    [J]. 2024 IEEE CONFERENCE ON VIRTUAL REALITY AND 3D USER INTERFACES ABSTRACTS AND WORKSHOPS, VRW 2024, 2024, : 12 - 17
  • [45] Click-based evidence for decaying weight distributions in search effectiveness metrics
    Zhang, Yuye
    Park, Laurence A. F.
    Moffat, Alistair
    [J]. INFORMATION RETRIEVAL, 2010, 13 (01): : 46 - 69
  • [46] ClickBAIT: Click-based Accelerated Incremental Training of Convolutional Neural Networks
    Teng, Ervin
    Falcao, Joao Diogo
    Huang, Rui
    Iannucci, Bob
    [J]. 2018 IEEE APPLIED IMAGERY PATTERN RECOGNITION WORKSHOP (AIPR), 2018,
  • [47] Usability and Security of Gaze-Based Graphical Grid Passwords
    Arianezhad, Majid
    Stebila, Douglas
    Mozaffari, Behzad
    [J]. FINANCIAL CRYPTOGRAPHY AND DATA SECURITY: FC 2013 WORKSHOPS, 2013, 7862 : 17 - 33
  • [48] A "click-based" porous organic polymer from tetrahedral building blocks
    Pandey, Prativa
    Farha, Omar K.
    Spokoyny, Alexander M.
    Mirkin, Chad A.
    Kanatzidis, Mercouri G.
    Hupp, Joseph T.
    Nguyen, SonBinh T.
    [J]. JOURNAL OF MATERIALS CHEMISTRY, 2011, 21 (06) : 1700 - 1703
  • [49] A two stage click-based library of protein tyrosine phosphatase inhibitors
    Xie, Jian
    Seto, Christopher T.
    [J]. BIOORGANIC & MEDICINAL CHEMISTRY, 2007, 15 (01) : 458 - 473
  • [50] A click-based modular approach to introduction of peroxides onto molecules and nanostructures
    Horn, Alissa
    Dussault, Patrick H.
    [J]. RSC ADVANCES, 2020, 10 (72) : 44408 - 44429