The Experts below are selected from a list of 651 Experts worldwide ranked by ideXlab platform

Paul John Steinbart - One of the best experts on this subject based on the ideXlab platform.

  • Keith et al. Effectiveness and Usability of Passphrases ABSTRACT The Effectiveness and Usability of Passphrases for Authentication
    2008
    Co-Authors: Mark Keith, Paul John Steinbart, Benjamin Shao
    Abstract:

    In developing Password policies, IT managers must strike a balance between security and memorability. Rules that improve structural integrity against attacks (e.g., increasing length and multiple Character types) may also result in Passwords that are difficult to remember. Recent technologies have relaxed the 8-Character Password constraint – permitting the creation of longer pass-“phrases ” consisting of multiple words. Psychology theories suggest users can remember passphrases at least as well as Passwords. This paper reports an experiment currently in progress that tests the usability of passphrases. Subjects are randomly assigned to three different Password creation techniques: a control group with no constraints, a secure group given strong Password requirements, and a passphrase group. It is expected that the passphrases group will have fewer failed login attempts than the secure group and no more failed login attempts than the control group. Practical implications include stronger authentication with reduced help desk costs

  • the usability of passphrases for authentication an empirical field study
    International Journal of Human-computer Studies \ International Journal of Man-machine Studies, 2007
    Co-Authors: Mark J Keith, Benjamin B M Shao, Paul John Steinbart
    Abstract:

    In developing Password policies, IT managers must strike a balance between security and memorability. Rules that improve structural integrity against attacks may also result in Passwords that are difficult to remember. Recent technologies have relaxed the 8-Character Password constraint to permit the creation of longer pass-''phrases'' consisting of multiple words. Longer passphrases are attractive because they can improve security by increasing the difficulty of brute-force attacks and they might also be easy to remember. Yet, no empirical evidence concerning the actual usability of passphrases exists. This paper presents the results of a 12-week experiment that examines users' experience and satisfaction with passphrases. Results indicate that passphrase users experienced a rate of unsuccessful logins due to memory recall failure similar to that of users of self-generated simple Passwords and stringent Passwords. However, passphrase users had more failed login attempts due to typographical errors than did users of either simple or highly secure Passwords. Moreover, although the typographical errors disappeared over time, passphrase users' initial problems negatively affected their end-of-experiment perceptions.

  • The effectiveness and usability of passphrases for authentication
    2005
    Co-Authors: Mark J Keith, Benjamin B M Shao, Paul John Steinbart
    Abstract:

    In developing Password policies, IT managers must strike a balance between security and memorability. Rules that improve structural integrity against attacks (e.g., increasing length and multiple Character types) may also result in Passwords that are difficult to remember. Recent technologies have relaxed the 8-Character Password constraint – permitting the creation of longer pass-“phrases” consisting of multiple words. Psychology theories suggest users can remember passphrases at least as well as Passwords. This paper reports an experiment currently in progress that tests the usability of passphrases. Subjects are randomly assigned to three different Password creation techniques: a control group with no constraints, a secure group given strong Password requirements, and a passphrase group. It is expected that the passphrases group will have fewer failed login attempts than the secure group and no more failed login attempts than the control group. Practical implications include stronger authentication with reduced help desk costs.

Andersen, Aleksander Sveløkken - One of the best experts on this subject based on the ideXlab platform.

  • Biometric Authentication and Identification using Keystroke Dynamics with Alert Levels
    Universitetet i Oslo, 2007
    Co-Authors: Andersen, Aleksander Sveløkken
    Abstract:

    Proper authentication is needed to avoid theft and destruction of data by unauthorized parties. This research proposes to add software biometrics to the authentication and verification process, using keystroke dynamics. The goal is to grant or revoke users privileges by distinguishing one user’s typing pattern from another. Login samples were recorded by monitoring keystroke parameters such as KeyDown time and KeyWait time, in an 8 Character Password. A system to generate user profiles, with the ability to accommodate continuous growth, was developed. By using appropriate Alert Levels, a 2.25% False Acceptance Rate and 4.17% False Rejection Rate was achieved. A method to recognize and identify users, based on one login sample, was able to trace 65% of the samples back to the original user. The work in this thesis was unable to find an applicable method for statistical pattern recognition. It concludes that by enabling a biometric keystroke dynamic authentication system, 97.75% of all false login attempts, with stolen but valid credentials, can be prevented, although with a potential downside of increasing the number of falsely rejected logins by 4.17%. However, as users grow accustomed to their Password, the false rejection rate will go down and the system will increase in reliability. Password DoS attacks as well as automated dictionary attacks will be prevented, but a potential increase in administration cost is probable because of altered user behavior due to physical or environmental changes.Master i nettverks- og systemadministrasjo

  • Authentication and Identification using Keystroke Dynamics with Alert Levels
    2007
    Co-Authors: Andersen, Aleksander Sveløkken
    Abstract:

    Proper authentication is needed to avoid theft and destruction of data by unauthorized parties. This research proposes to add software biometrics to the authentication and verification process, using keystroke dynamics. The goal is to grant or revoke users privileges by distinguishing one user’s typing pattern from another. Login samples were recorded by monitoring keystroke parameters such as KeyDown time and KeyWait time, in an 8 Character Password. A system to generate user profiles, with the ability to accommodate continuous growth, was developed. By using appropriate Alert Levels, a 2.25 % False Acceptance Rate and 4.17 % False Rejection Rate was achieved. A method to recognize and identify users, based on one login sample, was able to trace 65 % of the samples back to the original user. The work in this thesis was unable to find an applicable method for statistical pattern recognition. It concludes that by enabling a biometric keystroke dynamic authentication system, 97.75 % of all false login attempts, with stolen but valid credentials, can be prevented, although with a potential downside of increasing the number of falsely rejected logins by 4.17%. However, as users grow accustomed to their Password, the false rejection rate will go down and the system will increase in reliability. Password DoS attacks as well as automated dictionary attacks will be prevented, but a potential increase in administration cost is probable because of altered user behavior due to physical or environmental changes. 2 Acknowledgements To my mother; for making me believe in the Lock Ness monster. To my father; who taught me how to play chess at an early age, and not letting me win. To my sister; for constantly reminding me of the value and importance of honesty and justice. To my brother; for always challenging my every idea. for pushing me to improve. and for everything unsaid but recognized between us. You have all made a huge impact on who I am today, and for that; I am forever grateful

Mark J Keith - One of the best experts on this subject based on the ideXlab platform.

  • the usability of passphrases for authentication an empirical field study
    International Journal of Human-computer Studies \ International Journal of Man-machine Studies, 2007
    Co-Authors: Mark J Keith, Benjamin B M Shao, Paul John Steinbart
    Abstract:

    In developing Password policies, IT managers must strike a balance between security and memorability. Rules that improve structural integrity against attacks may also result in Passwords that are difficult to remember. Recent technologies have relaxed the 8-Character Password constraint to permit the creation of longer pass-''phrases'' consisting of multiple words. Longer passphrases are attractive because they can improve security by increasing the difficulty of brute-force attacks and they might also be easy to remember. Yet, no empirical evidence concerning the actual usability of passphrases exists. This paper presents the results of a 12-week experiment that examines users' experience and satisfaction with passphrases. Results indicate that passphrase users experienced a rate of unsuccessful logins due to memory recall failure similar to that of users of self-generated simple Passwords and stringent Passwords. However, passphrase users had more failed login attempts due to typographical errors than did users of either simple or highly secure Passwords. Moreover, although the typographical errors disappeared over time, passphrase users' initial problems negatively affected their end-of-experiment perceptions.

  • The effectiveness and usability of passphrases for authentication
    2005
    Co-Authors: Mark J Keith, Benjamin B M Shao, Paul John Steinbart
    Abstract:

    In developing Password policies, IT managers must strike a balance between security and memorability. Rules that improve structural integrity against attacks (e.g., increasing length and multiple Character types) may also result in Passwords that are difficult to remember. Recent technologies have relaxed the 8-Character Password constraint – permitting the creation of longer pass-“phrases” consisting of multiple words. Psychology theories suggest users can remember passphrases at least as well as Passwords. This paper reports an experiment currently in progress that tests the usability of passphrases. Subjects are randomly assigned to three different Password creation techniques: a control group with no constraints, a secure group given strong Password requirements, and a passphrase group. It is expected that the passphrases group will have fewer failed login attempts than the secure group and no more failed login attempts than the control group. Practical implications include stronger authentication with reduced help desk costs.

Benjamin B M Shao - One of the best experts on this subject based on the ideXlab platform.

  • the usability of passphrases for authentication an empirical field study
    International Journal of Human-computer Studies \ International Journal of Man-machine Studies, 2007
    Co-Authors: Mark J Keith, Benjamin B M Shao, Paul John Steinbart
    Abstract:

    In developing Password policies, IT managers must strike a balance between security and memorability. Rules that improve structural integrity against attacks may also result in Passwords that are difficult to remember. Recent technologies have relaxed the 8-Character Password constraint to permit the creation of longer pass-''phrases'' consisting of multiple words. Longer passphrases are attractive because they can improve security by increasing the difficulty of brute-force attacks and they might also be easy to remember. Yet, no empirical evidence concerning the actual usability of passphrases exists. This paper presents the results of a 12-week experiment that examines users' experience and satisfaction with passphrases. Results indicate that passphrase users experienced a rate of unsuccessful logins due to memory recall failure similar to that of users of self-generated simple Passwords and stringent Passwords. However, passphrase users had more failed login attempts due to typographical errors than did users of either simple or highly secure Passwords. Moreover, although the typographical errors disappeared over time, passphrase users' initial problems negatively affected their end-of-experiment perceptions.

  • The effectiveness and usability of passphrases for authentication
    2005
    Co-Authors: Mark J Keith, Benjamin B M Shao, Paul John Steinbart
    Abstract:

    In developing Password policies, IT managers must strike a balance between security and memorability. Rules that improve structural integrity against attacks (e.g., increasing length and multiple Character types) may also result in Passwords that are difficult to remember. Recent technologies have relaxed the 8-Character Password constraint – permitting the creation of longer pass-“phrases” consisting of multiple words. Psychology theories suggest users can remember passphrases at least as well as Passwords. This paper reports an experiment currently in progress that tests the usability of passphrases. Subjects are randomly assigned to three different Password creation techniques: a control group with no constraints, a secure group given strong Password requirements, and a passphrase group. It is expected that the passphrases group will have fewer failed login attempts than the secure group and no more failed login attempts than the control group. Practical implications include stronger authentication with reduced help desk costs.

Benjamin Shao - One of the best experts on this subject based on the ideXlab platform.

  • Keith et al. Effectiveness and Usability of Passphrases ABSTRACT The Effectiveness and Usability of Passphrases for Authentication
    2008
    Co-Authors: Mark Keith, Paul John Steinbart, Benjamin Shao
    Abstract:

    In developing Password policies, IT managers must strike a balance between security and memorability. Rules that improve structural integrity against attacks (e.g., increasing length and multiple Character types) may also result in Passwords that are difficult to remember. Recent technologies have relaxed the 8-Character Password constraint – permitting the creation of longer pass-“phrases ” consisting of multiple words. Psychology theories suggest users can remember passphrases at least as well as Passwords. This paper reports an experiment currently in progress that tests the usability of passphrases. Subjects are randomly assigned to three different Password creation techniques: a control group with no constraints, a secure group given strong Password requirements, and a passphrase group. It is expected that the passphrases group will have fewer failed login attempts than the secure group and no more failed login attempts than the control group. Practical implications include stronger authentication with reduced help desk costs