Show simple item record

dc.contributor.advisorBeyah, Raheem
dc.contributor.authorYang, Shukun
dc.date.accessioned2017-06-07T17:38:18Z
dc.date.available2017-06-07T17:38:18Z
dc.date.created2016-05
dc.date.issued2016-04-27
dc.date.submittedMay 2016
dc.identifier.urihttp://hdl.handle.net/1853/58192
dc.description.abstractTo keep password users from creating simple and common passwords, major websites and applications provide a password-strength measure, namely a password checker that displays instant password strength ratings in levels e.g., “strong”, “moderate”, and “weak”. While critical requirements for a password checker to be stringent have prevailed in the study of password security, we find that regardless of the stringency, such static checkers can leak information and actually help the adversary enhance the performance of their attacks. To address this weakness, we propose and devise the Dynamic Password Policy Generator, namely DPPG, to be an effective and usable alternative to the existing password strength checker. DPPG aims to enforce an evenly-distributed password space and generate dynamic policies for users to create passwords that are diverse and contribute to the overall security of the password database. Since DPPG is modular and can function with different underlying metrics for policy generation, we further introduce a diversity-based password security metric that evaluates the security of a password database in terms of password space and distribution. The metric is useful as a countermeasure to well-crafted offline cracking algorithms and theoretically illustrates why DPPG works well.
dc.format.mimetypeapplication/pdf
dc.language.isoen_US
dc.publisherGeorgia Institute of Technology
dc.subjectPassword
dc.subjectAuthentication
dc.subjectSecurity
dc.titleA diversity-based framework for dynamic password policy generation
dc.typeThesis
dc.description.degreeM.S.
dc.contributor.departmentElectrical and Computer Engineering
thesis.degree.levelMasters
dc.contributor.committeeMemberCopeland, John
dc.contributor.committeeMemberOwen, Henry
dc.date.updated2017-06-07T17:38:18Z


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record