【24h】

Where Do Security Policies Come From?

机译:安全策略从何而来?

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

We examine the password policies of 75 different websites. Our goal is understand the enormous diversity of requirements: some will accept simple six-character passwords, while others impose rules of great complexity on their users. We compare different features of the sites to find which characteristics are correlated with stronger policies. Our results are surprising: greater security demands do not appear to be a factor. The size of the site, the number of users, the value of the assets protected and the frequency of attacks show no correlation with strength. In fact we find the reverse: some of the largest, most attacked sites with greatest assets allow relatively weak passwords. Instead, we find that those sites that accept advertising, purchase sponsored links and where the user has a choice show strong inverse correlation with strength.rnWe conclude that the sites with the most restrictive password policies do not have greater security concerns, they are simply better insulated from the consequences of poor usability. Online retailers and sites that sell advertising must compete vigorously for users and traffic. In contrast to government and university sites, poor usability is a luxury they cannot afford. This in turn suggests that much of the extra strength demanded by the more restrictive policies is superfluous: it causes considerable inconvenience for negligible security improvement.
机译:我们研究了75个不同网站的密码策略。我们的目标是了解需求的多样性:有些将接受简单的六个字符的密码,而另一些则将非常复杂的规则强加给用户。我们比较了网站的不同特征,以发现哪些特征与更强大的政策相关。我们的结果令人惊讶:更高的安全性要求似乎并不是一个因素。站点的大小,用户数,受保护资产的价值以及攻击频率与强度无关。实际上,我们发现了相反的情况:一些资产最大,受攻击最多的站点,其密码相对较弱。取而代之的是,我们发现那些接受广告,购买赞助商链接并且用户可以选择的站点与强度之间呈现出强烈的反相关关系。我们得出结论,密码策略限制最严格的站点并没有更大的安全隐患,它们只是更好避免了易用性带来的后果。在线零售商和出售广告的网站必须积极争取用户和流量。与政府和大学站点相反,可用性差是他们无法负担的奢侈品。反过来,这表明限制性较高的策略所要求的许多额外强度是多余的:它给安全性的改善带来了极大的不便。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号