Simulating and modelling the effectiveness of graphical password intersection attacks

English, R. (2015) Simulating and modelling the effectiveness of graphical password intersection attacks. Concurrency and Computation: Practice and Experience, 27(12), pp. 3089-3107. (doi: 10.1002/cpe.3196)

Full text not currently available from Enlighten.

Abstract

Recognition-based graphical passwords (RBGPs) are often proposed as an alternative user authentication mechanism. However, discussion of attack resistance often lacks quantitative examination. Establishing the efficacy of countermeasures could allow selection of an appropriate countermeasure for the level of security required by a given system. Furthermore, this information could be used to construct a model to estimate the number of intersection attacks required before success. This research contributes to these goals by establishing effective countermeasures and a model for intersection attacks. The approach involves creating a simulation of intersection attacks using five possible countermeasures and performing analysis to determine efficacy. Results show that using dummy screens does not increase the number of attacks required. It is also shown that increasing the number of challenge screens can increase and reduce the number of attacks required. Also presented is a model for RBGP schemes that can be used to estimate the number of intersection attacks required for a RBGP scheme when configuration values such as the number of challenge screens are known. This allows a quantitative choice of countermeasure for intersection attacks and a calculation that can provide a basis of comparison with other RBGP schemes, which was previously not possible.

Item Type:Articles
Additional Information:Special Issue: Frontier technologies of trust computing and network security (TrustCom 2012).
Status:Published
Refereed:Yes
Glasgow Author(s) Enlighten ID:English, Dr Rosanne
Authors: English, R.
College/School:College of Science and Engineering > School of Computing Science
Journal Name:Concurrency and Computation: Practice and Experience
Publisher:Wiley
ISSN:1532-0626
ISSN (Online):1532-0634
Published Online:18 December 2013

University Staff: Request a correction | Enlighten Editors: Update this record