首页> 外文学位 >Password strength analysis: User coping mechanisms in password selection.
【24h】

Password strength analysis: User coping mechanisms in password selection.

机译:密码强度分析:密码选择中的用户应对机制。

获取原文
获取原文并翻译 | 示例

摘要

The security that passwords provide could be seriously flawed due to the way people cope with having to memorize and recall their passwords. The National Institute of Standards and Technology (NIST) standard that is used to measure the password strength, known as entropy, is designed for a single use and does not consider that users may choose to keep parts of their password across password changes. This study shows that a portion of users keep some information from previous passwords across changes. These habits which will be called coping mechanisms that over time serve to erode the protection provided by passwords past the minimum level of security provided by the password policy which can place both individuals and enterprises into danger. This is made even more apparent with data breaches become a common phenomenon in present day life serving to expose user's password to the world. It was found that the minimum level of security can no longer be provided after one disclosure of passwords in the Comprehensive 8 password policy, and after two disclosures in passwords in the Blacklist Hard and Basic 16 policy. Coping mechanisms are most prevalent in password policies that have many requirements placed on users. The Comprehensive 8 policy showed the most coping followed by the Blacklist Hard and Basic 16 policies.
机译:密码所提供的安全性可能会由于人们必须记住和记住密码的方式而严重受损。美国国家标准技术研究院(NIST)标准用于度量密码强度(称为熵),是为单次使用而设计的,并不认为用户可能会选择在更改密码时保留部分密码。这项研究表明,部分用户保留了更改期间以前的密码中的某些信息。这些习惯将被称为应对机制,随着时间的流逝,它们逐渐侵蚀密码所提供的保护,超出密码策略所提供的最低安全级别,这可能使个人和企业面临危险。随着数据泄露已成为当今用户暴露给用户的密码的普遍现象,这一点变得更加明显。结果发现,在“综合8”密码策略中一次披露密码后,以及在“黑名单”“硬”和“基本16”策略中两次披露密码后,便无法再提供最低的安全级别。应对机制在密码策略中最为普遍,对用户有很多要求。综合8政策表现最为出色,其次是黑名单硬政策和基本16政策。

著录项

  • 作者

    Curnett, Brian Thomas.;

  • 作者单位

    Purdue University.;

  • 授予单位 Purdue University.;
  • 学科 Computer science.;Cognitive psychology.;Information science.
  • 学位 M.S.
  • 年度 2015
  • 页码 97 p.
  • 总页数 97
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-17 11:52:41

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号