Shoulder surfing: From an experimental study to a comparative framework. Issue 130 (October 2019)
- Record Type:
- Journal Article
- Title:
- Shoulder surfing: From an experimental study to a comparative framework. Issue 130 (October 2019)
- Main Title:
- Shoulder surfing: From an experimental study to a comparative framework
- Authors:
- Bošnjak, Leon
Brumen, Boštjan - Abstract:
- Highlights: A comparative framework allows for an in-depth analysis of shoulder surfing. Novel hybrid authentication method based on associations is introduced. Empirical evidence shows graphical passwords are more vulnerable to shoulder surfing. Other factors also affect the probability of shoulder attacks being successful. Abstract: Shoulder surfing is an attack vector widely recognized as a real threat - enough to warrant researchers dedicating a considerable effort toward designing novel authentication methods to be shoulder surfing resistant. Despite a multitude of proposed solutions over the years, few have employed empirical evaluations and comparisons between different methods, and our understanding of the shoulder surfing phenomenon remains limited. Barring the challenges in experimental design, the reason for that can be primarily attributed to the lack of objective and comparable vulnerability measures. In this paper, we develop an ensemble of vulnerability metrics, a first endeavour toward a comprehensive assessment of a given method's susceptibility to observational attacks. In the largest on-site shoulder surfing experiment ( n = 274) to date, we verify the model on four conceptually different authentication methods in two observation scenarios. On the example of a novel hybrid authentication method based on associations, we explore the effect of input type on the adversary's effectiveness. We provide first empirical evidence that graphical passwords are easierHighlights: A comparative framework allows for an in-depth analysis of shoulder surfing. Novel hybrid authentication method based on associations is introduced. Empirical evidence shows graphical passwords are more vulnerable to shoulder surfing. Other factors also affect the probability of shoulder attacks being successful. Abstract: Shoulder surfing is an attack vector widely recognized as a real threat - enough to warrant researchers dedicating a considerable effort toward designing novel authentication methods to be shoulder surfing resistant. Despite a multitude of proposed solutions over the years, few have employed empirical evaluations and comparisons between different methods, and our understanding of the shoulder surfing phenomenon remains limited. Barring the challenges in experimental design, the reason for that can be primarily attributed to the lack of objective and comparable vulnerability measures. In this paper, we develop an ensemble of vulnerability metrics, a first endeavour toward a comprehensive assessment of a given method's susceptibility to observational attacks. In the largest on-site shoulder surfing experiment ( n = 274) to date, we verify the model on four conceptually different authentication methods in two observation scenarios. On the example of a novel hybrid authentication method based on associations, we explore the effect of input type on the adversary's effectiveness. We provide first empirical evidence that graphical passwords are easier to observe; however, that does not necessarily mean that the observed information will allow the attacker to guess the victim's password easier. An in-depth analysis of individual metrics within the clusters offers insight into many additional aspects of the shoulder surfing attack not explored before. Our comparative framework makes an advancement in evaluation of shoulder surfing and furthers our understanding of observational attacks. The results have important implications for future shoulder surfing studies and the field of Password Security as a whole. … (more)
- Is Part Of:
- International journal of human-computer studies. Issue 130(2019)
- Journal:
- International journal of human-computer studies
- Issue:
- Issue 130(2019)
- Issue Display:
- Volume 130, Issue 130 (2019)
- Year:
- 2019
- Volume:
- 130
- Issue:
- 130
- Issue Sort Value:
- 2019-0130-0130-0000
- Page Start:
- 1
- Page End:
- 20
- Publication Date:
- 2019-10
- Subjects:
- Shoulder surfing -- Textual passwords -- Graphical passwords -- Authentication -- Comparative framework -- Vulnerability evaluation
Human-machine systems -- Periodicals
Systems engineering -- Periodicals
Human engineering -- Periodicals
Human engineering
Human-machine systems
Systems engineering
Periodicals
Electronic journals
004.019 - Journal URLs:
- http://www.sciencedirect.com/science/journal/10715819 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.ijhcs.2019.04.003 ↗
- Languages:
- English
- ISSNs:
- 1071-5819
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 4542.288100
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 14769.xml