首页> 外文会议>2013 International Conference on Computer Applications Technology >Resolving the password security purgatory in the contexts of technology, security and human factors
【24h】

Resolving the password security purgatory in the contexts of technology, security and human factors

机译:在技​​术,安全性和人为因素的背景下解决密码安全炼狱

获取原文
获取原文并翻译 | 示例

摘要

Passwords are the most popular and constitute the first line of defence in computer-based security systems; despite the existence of more attack-resistant authentication schemes. In order to enhance password security, it is imperative to strike a balance between having enough rules to maintain good security and not having too many rules that would compel users to take evasive actions which would, in turn, compromise security. It is noted that the human factor is the most critical element in the security system for at least three possible reasons; it is the weakest link, the only factor that exercises initiatives, as well as the factor that transcends all the other elements of the entire system. This illustrates the significance of social engineering in security designs, and the fact that security is indeed a function of both technology and human factors; bearing in mind the fact that there can be no technical hacking in vacuum. This paper examines the current divergence among security engineers as regards the rules governing best practices in the use of passwords: should they be written down or memorized; changed frequently or remain permanent? It also attempts to elucidate the facts surrounding some of the myths associated with computer security. This paper posits that destitution of requisite balance between the factors of technology and factors of humanity is responsible for the purgatory posture of password security related problems. It is thus recommended that, in the handling of password security issues, human factors should be given priority over technological factors. The paper proposes the use of the (k, n)- Threshold Scheme, such as the Shamir's secret-sharing scheme, to enhance the security of the password repository. This presupposes an inclination towards writing down the password: after all, Diamond, Platinum, Gold and Silver are not memorised; they are stored.
机译:密码是最流行的密码,并且是基于计算机的安全系统中的第一道防线。尽管存在更多抗攻击的身份验证方案。为了增强密码的安全性,必须在拥有足够的规则来维持良好的安全性与没有太多的规则(必须迫使用户采取逃避措施,进而损害安全性)之间取得平衡。值得注意的是,出于至少三个可能的原因,人为因素是安全系统中最关键的因素。它是最薄弱的环节,是行使主动权的唯一因素,也是超越整个系统所有其他要素的因素。这说明了社会工程学在安全设计中的重要性,以及安全确实是技术和人为因素的函数这一事实。请记住,不能在真空中进行技术黑客攻击。本文研究了安全工程师之间在管理密码使用最佳实践的规则方面的当前分歧:应将其写下或记住;经常更改还是保持不变?它还试图阐明与计算机安全性相关的一些神话事实。本文认为,技术因素和人为因素之间必要的平衡的破坏是造成密码安全相关问题的炼狱态势的原因。因此,建议在处理密码安全性问题时,应优先考虑人为因素而不是技术因素。本文提出了使用(k,n)-阈值方案(例如Shamir的秘密共享方案)来增强密码存储库的安全性。前提是倾向于写下密码:毕竟,钻石,铂金,黄金和白银没有被记住;它们被存储。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号