Breaking undercover: exploiting design flaws and nonuniform human behavior

Breaking undercover: exploiting design flaws and nonuniform human behavior
复制标题

打破秘密:利用设计缺陷和不一致的人类行为

DOI:
10.1145/2078827.2078834
复制
发表时间:
2011
期刊:
Symposium On Usable Privacy and Security
影响因子:
--
通讯作者:
Mario Cagalj
Mario Cagalj
中科院分区:
--
文献类型:
--
作者:
T. Perković;Shujun Li;Asma Mumtaz;S. A. Khayam;Yousra Javed;Mario Cagalj

文献摘要

被引文献

相似文献

本文报告了对在CHI 2008上提出的针对被动观察者的人体认证方案Undercover的两种攻击。第一种攻击利用了响应身份验证挑战的不一致人类行为,第二种攻击基于从身份验证挑战或攻击者可见的响应中泄露的信息。第二种攻击可以概括为破坏在Pervasive 2009上提出的两种替代的Undercover设计。所有攻击都利用了Undercover实现的设计缺陷。理论和实验分析表明,这两种攻击都能以O(10)的时间复杂度泄露用户密码。这两种攻击都是通过使用在一项有28名参与者的用户研究中收集的登录数据进行验证的。我们还提出了一些增强功能,使卧底安全的攻击,本文中报道的。我们在打破和改善卧底方面的研究导致了两个更广泛的影响。首先,再次强调了安全相关人机界面设计的“细节决定成败”原则。其次,它揭示了安全性和可用性之间的微妙关系:人类用户可能会以不安全的方式危害系统的安全性。为了设计一个安全的人机界面,设计师应该特别注意界面的任何细节可能产生的负面影响,包括人类用户如何与系统交互。
This paper reports two attacks on Undercover, a human authentication scheme against passive observers proposed at CHI 2008. The first attack exploits nonuniform human behavior in responding to authentication challenges and the second one is based on information leaked from authentication challenges or responses visible to the attacker. The second attack can be generalized to break two alternative Undercover designs presented at Pervasive 2009. All the attacks exploit design flaws of the Undercover implementations. Theoretical and experimental analyses show that both attacks can reveal the user's password with high probability with O(10) observed login sessions. Both attacks were verified by using the login data collected in a user study with 28 participants. We also propose some enhancements to make Undercover secure against the attacks reported in this paper. Our research in breaking and improving Undercover leads to two broader implications. First, it reemphasizes the principle of "devil is in details" for the design of security-related human-computer interface. Secondly, it reveals a subtle relationship between security and usability: human users may behave in an insecure way to compromise the security of a system. To design a secure human-computer interface, designers should pay special attention to possible negative influence of any detail of the interface including how human users interact with the system.