See you next time: a model for modern shoulder surfers

Oliver Wiese, Volker Roth
{"title":"See you next time: a model for modern shoulder surfers","authors":"Oliver Wiese, Volker Roth","doi":"10.1145/2935334.2935388","DOIUrl":null,"url":null,"abstract":"Friends, family and colleagues at work may repeatedly observe how their peers unlock their smartphones. These \"insiders\" may combine multiple partial observations to form a hypothesis of a target's secret. This changing landscape requires that we update the methods used to assess the security of unlocking mechanisms against human shoulder surfing attacks. In our paper, we introduce a methodology to study shoulder surfing risks in the insider threat model. Our methodology dissects the authentication process into minimal observations by humans. Further processing is based on simulations. The outcome is an estimate of the number of observations needed to break a mechanism. The flexibility of this approach benefits the design of new mechanisms. We demonstrate the application of our methodology by performing an analysis of the SwiPIN scheme published at CHI 2015. Our results indicate that SwiPIN can be defeated reliably by a majority of the population with as few as 6 to 11 observations.","PeriodicalId":420843,"journal":{"name":"Proceedings of the 18th International Conference on Human-Computer Interaction with Mobile Devices and Services","volume":"176 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2016-09-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"25","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the 18th International Conference on Human-Computer Interaction with Mobile Devices and Services","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/2935334.2935388","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 25

Abstract

Friends, family and colleagues at work may repeatedly observe how their peers unlock their smartphones. These "insiders" may combine multiple partial observations to form a hypothesis of a target's secret. This changing landscape requires that we update the methods used to assess the security of unlocking mechanisms against human shoulder surfing attacks. In our paper, we introduce a methodology to study shoulder surfing risks in the insider threat model. Our methodology dissects the authentication process into minimal observations by humans. Further processing is based on simulations. The outcome is an estimate of the number of observations needed to break a mechanism. The flexibility of this approach benefits the design of new mechanisms. We demonstrate the application of our methodology by performing an analysis of the SwiPIN scheme published at CHI 2015. Our results indicate that SwiPIN can be defeated reliably by a majority of the population with as few as 6 to 11 observations.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
下期见:现代肩部冲浪者的典范
朋友、家人和同事可能会反复观察他们的同龄人是如何解锁智能手机的。这些“内部人士”可能会将多个部分观察结果结合起来,形成对目标秘密的假设。这种不断变化的环境要求我们更新用于评估针对人类肩部冲浪攻击的解锁机制安全性的方法。在本文中,我们引入了一种方法来研究内部威胁模型中的肩部冲浪风险。我们的方法将认证过程分解为人类的最小观察。进一步的处理是基于仿真的。结果是对打破一个机制所需的观测次数的估计。这种方法的灵活性有利于新机制的设计。我们通过对CHI 2015上发布的SwiPIN方案进行分析来演示我们方法的应用。我们的研究结果表明,SwiPIN可以被大多数人可靠地击败,只需6到11次观察。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A longitudinal evaluation of the acceptability and impact of a diet diary app for older adults with age-related macular degeneration Session details: Text entry Nail+: sensing fingernail deformation to detect finger force touch interactions on rigid surfaces Feasibility of using haptic directions through maps with a tablet and smart watch for people who are blind and visually impaired It's not how you stand, it's how you move: F-formations and collaboration dynamics in a mobile learning game
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1