TC: Small: An Empirical Study of Text-based Passwords and Their Users
TC:小:基于文本的密码及其用户的实证研究
基本信息
- 批准号:1116776
- 负责人:
- 金额:$ 49.45万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2011
- 资助国家:美国
- 起止时间:2011-09-01 至 2014-08-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Text-based passwords are the most commonly used mechanism for authenticating users to computer systems, but are often easy for attackers to compromise. To mitigate the danger of such attacks, system administrators use password-composition policies, which force newly created passwords to adhere to a set of requirements intended to make them harder to guess. Although it is generally believed that reasonable password-composition policies make passwords harder to guess, and hence more secure, research has not been able to precisely quantify the level of resistance to password guessing provided by different password-composition policies or the individual requirements of which they are comprised. Beyond their affect on the guessability of passwords, password-composition policies also affect users' behavior. For example, certain password-composition policies that lead to more-difficult-to-predict passwords may also lead users to write down their passwords more readily, reuse them across accounts, or forget them more often. Such behavior can both affect an adversary's ability to guess passwords, and raise the cost of administering a system.This project will substantially contribute to the understanding of the effects of password-composition policies on the security and usability of text-based passwords. The results of this research will be applicable to almost all computer systems that use text-based passwords, and will allow administrators to better select suitable password-composition policies, thus rendering them less susceptible to account compromise. More specifically, this project will involve collecting sets of passwords (or data about passwords) created under different password-composition policies and data about the associated user behaviors, and analyzing them for security and usability. Sets of up to tens of thousands of passwords or statistics about them will be collected via online studies, actual field data from two institutions, and from paper-and-pencil surveys and lab studies. This data will be analyzed using several new methods, including an approach for calculating how long it would take for various state-of-the-art password-guessing tools or algorithms to guess the passwords, and a new method for approximating the entropy of passwords from smaller datasets than was previously feasible. Based on this methodology, this research will: (1) measure the guessability of passwords generated under multiple different password-composition policies more accurately than was previously possible; (2) empirically assess the usefulness of entropy approximations (a common, but questioned, measure of password strength) as a measure of password guessability by state-of-the-art password-guessing algorithms; and (3) compare the usability of and user sentiment engendered by each password-composition policy to develop a holistic understanding of the merits of policies. This will enable the development of a set of actionable guidelines for administrators that will help them select password-composition policies appropriate for their user populations and security requirements. Two graduate students will be directly involved in this research project.
基于文本的密码是对计算机系统的用户进行身份验证的最常用机制,但通常很容易被攻击者攻破。为了减轻此类攻击的危险,系统管理员使用密码组合策略,该策略强制新创建的密码遵守一组要求,以使其更难被猜测。虽然人们普遍认为合理的密码组合策略使密码更难被猜测,从而更安全,但研究还不能精确地量化不同密码组合策略所提供的抗密码猜测的程度或它们所包含的单个要求。密码组合策略除了影响密码的可猜测性外,还会影响用户的行为。例如,某些导致密码更难预测的密码组合策略也可能导致用户更容易写下密码,跨帐户重复使用密码,或者更频繁地忘记密码。这种行为既会影响攻击者猜测密码的能力,又会增加管理系统的成本。该项目将大大有助于理解密码组合策略对基于文本的密码的安全性和可用性的影响。这项研究的结果将适用于几乎所有使用基于文本的密码的计算机系统,并将允许管理员更好地选择合适的密码组合策略,从而使他们更不容易受到帐户泄露的影响。更具体地说,该项目将包括收集在不同密码组合策略下创建的密码集(或有关密码的数据)以及相关用户行为的数据,并对其进行安全性和可用性分析。将通过在线研究、两家机构的实际现场数据、纸笔调查和实验室研究收集多达数万个密码或有关密码的统计数据。这些数据将使用几种新方法进行分析,包括计算各种最先进的密码猜测工具或算法猜测密码所需时间的方法,以及从比以前可行的更小的数据集中近似密码熵的新方法。基于该方法,本研究将:(1)比以前更准确地测量在多种不同密码组合策略下生成的密码的可猜测性;(2)通过最先进的密码猜测算法,经验性地评估熵近似(一种常见但受到质疑的密码强度度量)作为密码猜测性度量的有用性;(3)比较每个密码组合策略的可用性和用户情绪,以全面了解策略的优点。这将为管理员开发一套可操作的指导方针,帮助他们选择适合其用户群和安全需求的密码组合策略。两名研究生将直接参与这个研究项目。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Ljudevit Bauer其他文献
Ljudevit Bauer的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Ljudevit Bauer', 18)}}的其他基金
Collaborative Research: NSF-BSF: SaTC: CORE: Small: Detecting malware with machine learning models efficiently and reliably
协作研究:NSF-BSF:SaTC:核心:小型:利用机器学习模型高效可靠地检测恶意软件
- 批准号:
2338301 - 财政年份:2024
- 资助金额:
$ 49.45万 - 项目类别:
Continuing Grant
SaTC: CORE: Medium: Collaborative: Using Machine Learning to Build More Resilient and Transparent Computer Systems
SaTC:核心:媒介:协作:使用机器学习构建更具弹性和透明的计算机系统
- 批准号:
1801391 - 财政年份:2018
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
Student Travel Grants for the 2014 Network and Distributed System Security Symposium
2014 年网络与分布式系统安全研讨会学生旅费资助
- 批准号:
1354080 - 财政年份:2013
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
TC: Small: Towards precise specification of logic-based acces-control policies
TC:小:迈向基于逻辑的访问控制策略的精确规范
- 批准号:
1018211 - 财政年份:2010
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
Enabling Practical Cross-domain Logic-based Access Control
实现实用的基于跨域逻辑的访问控制
- 批准号:
0917047 - 财政年份:2009
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
CT-M: Usable Security for Digital Home Storage
CT-M:数字家庭存储的可用安全性
- 批准号:
0831407 - 财政年份:2008
- 资助金额:
$ 49.45万 - 项目类别:
Continuing Grant
CT-ISG: Collaborative Research: Trustworthy Enforcement of Domain-Independent Run-Time Policies
CT-ISG:协作研究:域独立运行时策略的可信执行
- 批准号:
0716216 - 财政年份:2007
- 资助金额:
$ 49.45万 - 项目类别:
Continuing Grant
ITR: Defending Against Virus Propagation on the Internet
ITR:防御互联网上的病毒传播
- 批准号:
0326472 - 财政年份:2003
- 资助金额:
$ 49.45万 - 项目类别:
Continuing Grant
相似国自然基金
基于TREM2/SYK介导的小胶质细胞极化研究经验方“无忧汤”抗睡眠障碍的作用机制
- 批准号:JCZRLH202500068
- 批准年份:2025
- 资助金额:0.0 万元
- 项目类别:省市级项目
新冠疫情下小微企业的经营风险与公共政策效果评估:来自餐饮企业的经验证据
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
小微企业减税效应及税负归宿研究:实证评估与政策优化
- 批准号:
- 批准年份:2022
- 资助金额:30 万元
- 项目类别:青年科学基金项目
基于混合参数模型非小细胞肺癌免疫疗法价值评估框架的构建及实证研究
- 批准号:
- 批准年份:2021
- 资助金额:10.0 万元
- 项目类别:省市级项目
5-羟色胺及受体调控获胜经验影响舞毒蛾卵平腹小蜂极端打斗行为机制研究
- 批准号:
- 批准年份:2021
- 资助金额:30 万元
- 项目类别:青年科学基金项目
超网络同构/异构嵌入视角下小微企业协同创业行为的演化机制:浙江数字产业群的经验证据
- 批准号:LY21G020003
- 批准年份:2020
- 资助金额:0.0 万元
- 项目类别:省市级项目
基于经验小波变换的流体管网泄漏多方向多模态声发射时频定位方法研究
- 批准号:61703066
- 批准年份:2017
- 资助金额:18.0 万元
- 项目类别:青年科学基金项目
基于声发射信号改进经验小波分析的钢桥面板疲劳裂纹定量监测方法研究
- 批准号:51708164
- 批准年份:2017
- 资助金额:23.0 万元
- 项目类别:青年科学基金项目
经验小波变换理论及其在机械故障诊断中的应用研究
- 批准号:51505002
- 批准年份:2015
- 资助金额:20.0 万元
- 项目类别:青年科学基金项目
基于自适应样条小波的经验模态分解研究
- 批准号:11226335
- 批准年份:2012
- 资助金额:3.0 万元
- 项目类别:数学天元基金项目
相似海外基金
The Empirical Study of Gender (EGEN) Research Network: Small Research Prizes to Graduate Students and Early Career Faculty
性别实证研究 (EGEN) 研究网络:为研究生和早期职业教师提供小型研究奖
- 批准号:
2215500 - 财政年份:2022
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
Empirical Studies on Inclusiveness and Exclusiveness of Sharing of Technologies in East African Small and Medium-sized Manufacturers
东非中小型制造商技术共享包容性与排他性实证研究
- 批准号:
21H03706 - 财政年份:2021
- 资助金额:
$ 49.45万 - 项目类别:
Grant-in-Aid for Scientific Research (B)
RI: Small: New Directions in Probabilistic Deep Learning: Exponential Families, Bayesian Nonparametrics and Empirical Bayes
RI:小:概率深度学习的新方向:指数族、贝叶斯非参数和经验贝叶斯
- 批准号:
2127869 - 财政年份:2021
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
NSF-BSF: RI: Small: Efficient Transformers via Formal and Empirical Analysis
NSF-BSF:RI:小型:通过形式和经验分析的高效变压器
- 批准号:
2113530 - 财政年份:2021
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
On Property Liability Insurance Demand of Small and Medium-sized Enterprises- Empirical Evidence Based on Finance and Insurance Theories-
论中小企业财产责任保险需求——基于金融保险理论的经验证据——
- 批准号:
20K01756 - 财政年份:2020
- 资助金额:
$ 49.45万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
CIF: Small: Fundamental Limits of Empirical Risk Minimization in High Dimensions: A Unifying Gaussian Processes Approach
CIF:小:高维经验风险最小化的基本限制:统一高斯过程方法
- 批准号:
2009030 - 财政年份:2020
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
OAC Core: Small: Devising Data-driven Methodologies by Employing Large-scale Empirical Data to Fingerprint, Attribute, Remediate and Analyze Internet-scale IoT Maliciousness
OAC 核心:小型:通过使用大规模经验数据来指纹识别、归因、修复和分析互联网规模的物联网恶意行为,设计数据驱动的方法
- 批准号:
1953051 - 财政年份:2019
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
Theoretical and Empirical Research on Project-Based Budgeting System for Small and Medium Civil Engineering Construction Companies
中小型土木工程施工企业项目预算制度的理论与实证研究
- 批准号:
19K01993 - 财政年份:2019
- 资助金额:
$ 49.45万 - 项目类别:
Grant-in-Aid for Scientific Research (C)
OAC Core: Small: Devising Data-driven Methodologies by Employing Large-scale Empirical Data to Fingerprint, Attribute, Remediate and Analyze Internet-scale IoT Maliciousness
OAC 核心:小型:通过使用大规模经验数据来指纹识别、归因、修复和分析互联网规模的物联网恶意行为,设计数据驱动的方法
- 批准号:
1907821 - 财政年份:2019
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant
NeTS: Small: Exploring the Design, Implementation, Operation Issues of Cellular IoT via Formal Analysis and Empirical Validation
NeTS:小型:通过形式分析和实证验证探索蜂窝物联网的设计、实施和操作问题
- 批准号:
1814551 - 财政年份:2018
- 资助金额:
$ 49.45万 - 项目类别:
Standard Grant