A novel password policy focusing on altering user password selection habits: A statistical analysis on breached data

dc.contributor.authorGüven, Ebu Yusuf
dc.contributor.authorBoyacı, Ali
dc.contributor.authorAydın, Muhammed Ali
dc.date.accessioned2022-09-14T07:41:56Z
dc.date.available2022-09-14T07:41:56Z
dc.date.issued2022en_US
dc.departmentFakülteler, Mühendislik Fakültesi, Bilgisayar Mühendisliği Bölümüen_US
dc.description.abstractOnline services generally employ password-based systems to enable users to access personal/private con- tent. These services also force their users to change their passwords periodically under specific policies to increase security. However, analysis of breached data reveals that current policies do not consider user password selection habits and pose critical security and privacy concerns. Additionally, when passwords are leaked, attackers have the opportunity to study - and possibly identify - the structure or pattern of the user password selection set. This way, attackers could predict the next password or reduce the search space considerably in their attacks. Therefore, this study proposes a novel behavior-based pass- word policy to increase the present security level and avoid further exploitations if a breach occurs. This study uses statistical methods and visualization techniques to examine the password selection behaviors of over ten million UserID-password pairs collected from anonymously shared data breaches. The data set is anonymized while keeping the uniqueness of userID-password pairs and shared with other researchers along with extracted features. Results show that user password selection patterns can be generalized and used to increase the success rate of attacks.en_US
dc.identifier.doi10.1016/j.cose.2021.102560en_US
dc.identifier.scopus2-s2.0-85121254980en_US
dc.identifier.scopusqualityN/Aen_US
dc.identifier.urihttps://hdl.handle.net/11467/5347
dc.identifier.urihttps://doi.org/10.1016/j.cose.2021.102560
dc.identifier.volume113en_US
dc.identifier.wosWOS:000754413100012en_US
dc.identifier.wosqualityQ2en_US
dc.indekslendigikaynakWeb of Scienceen_US
dc.indekslendigikaynakScopusen_US
dc.language.isoenen_US
dc.publisherElsevieren_US
dc.relation.ispartofComputers & Securityen_US
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/embargoedAccessen_US
dc.subjectData Breachen_US
dc.subjectPassword Selection Habitsen_US
dc.subjectPassword Patternsen_US
dc.subjectPassword Policen_US
dc.subjectBrute Force Attacken_US
dc.titleA novel password policy focusing on altering user password selection habits: A statistical analysis on breached dataen_US
dc.typeArticleen_US

Dosyalar

Orijinal paket
Listeleniyor 1 - 1 / 1
Küçük Resim Yok
İsim:
1-s2.0-S0167404821003849-main.pdf
Boyut:
2.52 MB
Biçim:
Adobe Portable Document Format
Açıklama:
Lisans paketi
Listeleniyor 1 - 1 / 1
Küçük Resim Yok
İsim:
license.txt
Boyut:
1.56 KB
Biçim:
Item-specific license agreed upon to submission
Açıklama: