评估用户构建强密码能力的情境感知用户界面:概念架构

Eliana Stavrou
{"title":"评估用户构建强密码能力的情境感知用户界面:概念架构","authors":"Eliana Stavrou","doi":"10.1109/CyberSA.2017.8073385","DOIUrl":null,"url":null,"abstract":"Text-based passwords are still one of the main techniques to authenticate the users. Although a variety of measures (e.g. awareness activities, password-strength checkers, password-composition policies, etc.) are taken to prevent users from selecting weak passwords, the problem remains. A main factor that leads to weak passwords is the lack of awareness on what constitutes a strong password. Organizations should assess the users' ability to construct a strong password through the assessment of their password's strength, and taking into consideration the users' practices that are typically applied when selecting a password. In this way, organizations can be aware of the situation, that is, if their users follow good or bad password construction practices. Depending on the practice utilized, the organization's security level can be affected. Bad password construction practices can lead to weak passwords which can increase the risk of unauthorized access. Therefore, organizations should target for good practices to be utilized by their users in an effort to decrease the possibility of unauthorized access. A typical way to assess a password's strength is by trying to crack it using password cracking tools. An assessor, e.g. system administrator, requires a fair amount of knowledge on how password cracking tools operate and need to be configured. Also, it is essential to be aware of the bad practices that users typically utilize. Such knowledge is not always present. Furthermore, these tools and their respective graphical user interface, have not been designed with the objective of assessing the users' awareness level against bad password construction practices. This paper proposes a conceptual architecture to assist in designing a situation-aware user interface to assess users' ability to construct a password that is not easily crackable. An initial mock prototype has been developed to realize the proposed architecture and identify the main features of the user interface.","PeriodicalId":365296,"journal":{"name":"2017 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA)","volume":null,"pages":null},"PeriodicalIF":0.0000,"publicationDate":"2017-06-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":"{\"title\":\"A situation-aware user interface to assess users' ability to construct strong passwords: A conceptual architecture\",\"authors\":\"Eliana Stavrou\",\"doi\":\"10.1109/CyberSA.2017.8073385\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Text-based passwords are still one of the main techniques to authenticate the users. Although a variety of measures (e.g. awareness activities, password-strength checkers, password-composition policies, etc.) are taken to prevent users from selecting weak passwords, the problem remains. A main factor that leads to weak passwords is the lack of awareness on what constitutes a strong password. Organizations should assess the users' ability to construct a strong password through the assessment of their password's strength, and taking into consideration the users' practices that are typically applied when selecting a password. In this way, organizations can be aware of the situation, that is, if their users follow good or bad password construction practices. Depending on the practice utilized, the organization's security level can be affected. Bad password construction practices can lead to weak passwords which can increase the risk of unauthorized access. Therefore, organizations should target for good practices to be utilized by their users in an effort to decrease the possibility of unauthorized access. A typical way to assess a password's strength is by trying to crack it using password cracking tools. An assessor, e.g. system administrator, requires a fair amount of knowledge on how password cracking tools operate and need to be configured. Also, it is essential to be aware of the bad practices that users typically utilize. Such knowledge is not always present. Furthermore, these tools and their respective graphical user interface, have not been designed with the objective of assessing the users' awareness level against bad password construction practices. This paper proposes a conceptual architecture to assist in designing a situation-aware user interface to assess users' ability to construct a password that is not easily crackable. An initial mock prototype has been developed to realize the proposed architecture and identify the main features of the user interface.\",\"PeriodicalId\":365296,\"journal\":{\"name\":\"2017 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA)\",\"volume\":null,\"pages\":null},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2017-06-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"6\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2017 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/CyberSA.2017.8073385\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 International Conference On Cyber Situational Awareness, Data Analytics And Assessment (Cyber SA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CyberSA.2017.8073385","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

摘要

基于文本的密码仍然是验证用户身份的主要技术之一。虽然采取了各种措施(例如意识活动、密码强度检查器、密码组合策略等)来防止用户选择弱密码,但问题仍然存在。导致弱密码的一个主要因素是缺乏对强密码构成的认识。组织应该通过评估用户密码的强度来评估用户构建强密码的能力,并考虑用户在选择密码时通常采用的做法。通过这种方式,组织可以了解情况,即他们的用户是否遵循了好的或坏的密码构造实践。根据所使用的实践,组织的安全级别可能会受到影响。不良的密码构造实践可能导致弱密码,从而增加未经授权访问的风险。因此,组织应该以用户使用的良好实践为目标,努力减少未经授权访问的可能性。评估密码强度的典型方法是尝试使用密码破解工具来破解它。评估员,例如系统管理员,需要对密码破解工具的操作和配置有相当多的了解。此外,了解用户通常使用的不良实践也很重要。这样的知识并不总是存在。此外,这些工具及其各自的图形用户界面的设计目的不是评估用户对不良密码构建实践的意识水平。本文提出了一个概念架构,以协助设计情境感知的用户界面,以评估用户构建不易被破解的密码的能力。已经开发了一个初始模拟原型来实现所提出的体系结构并确定用户界面的主要特征。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
A situation-aware user interface to assess users' ability to construct strong passwords: A conceptual architecture
Text-based passwords are still one of the main techniques to authenticate the users. Although a variety of measures (e.g. awareness activities, password-strength checkers, password-composition policies, etc.) are taken to prevent users from selecting weak passwords, the problem remains. A main factor that leads to weak passwords is the lack of awareness on what constitutes a strong password. Organizations should assess the users' ability to construct a strong password through the assessment of their password's strength, and taking into consideration the users' practices that are typically applied when selecting a password. In this way, organizations can be aware of the situation, that is, if their users follow good or bad password construction practices. Depending on the practice utilized, the organization's security level can be affected. Bad password construction practices can lead to weak passwords which can increase the risk of unauthorized access. Therefore, organizations should target for good practices to be utilized by their users in an effort to decrease the possibility of unauthorized access. A typical way to assess a password's strength is by trying to crack it using password cracking tools. An assessor, e.g. system administrator, requires a fair amount of knowledge on how password cracking tools operate and need to be configured. Also, it is essential to be aware of the bad practices that users typically utilize. Such knowledge is not always present. Furthermore, these tools and their respective graphical user interface, have not been designed with the objective of assessing the users' awareness level against bad password construction practices. This paper proposes a conceptual architecture to assist in designing a situation-aware user interface to assess users' ability to construct a password that is not easily crackable. An initial mock prototype has been developed to realize the proposed architecture and identify the main features of the user interface.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A methodology for testing virtualisation security Visualisation of device datasets to assist digital forensic investigation Random forest explorations for URL classification Cybersecurity situational awareness taxonomy Stock market reaction to data breaches: The moderating role of corporate social responsibility
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1