facing the facts about image type in recognition-based graphical passwords

25
Facing the Facts about Image Type in Recognition-Based Graphical Passwords Max Hlywa Department of Psychology Carleton University Ottawa, Canada Robert Biddle School of Computer Science Carleton University Ottawa, Canada Andre S. Patrick Department of Psychology Carleton University Ottawa, Canada ADLab 4/9 ACSAC 2011

Upload: missy

Post on 23-Feb-2016

41 views

Category:

Documents


0 download

DESCRIPTION

Facing the Facts about Image Type in Recognition-Based Graphical Passwords. ACSAC 2011. Max Hlywa Department of Psychology Carleton University Ottawa, Canada. Robert Biddle School of Computer Science Carleton University Ottawa, Canada. Andre S. Patrick Department of Psychology - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Facing the Facts about Image Type in Recognition-Based

Graphical PasswordsMax HlywaDepartment of

PsychologyCarleton University

Ottawa, Canada

Robert BiddleSchool of Computer

ScienceCarleton University

Ottawa, Canada

Andre S. PatrickDepartment of

PsychologyCarleton University

Ottawa, Canada

ADLab 4/9

ACSAC 2011

Page 2: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

OutlineIntroductionBackgroundFirst StudySecond StudyDiscussionConclusions

Page 3: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

IntroductionCurrent security systems suffer is because

they often fail to incorporate human factors knowledge in their design.

A usable password must be easy to remember. However, a secure password must be hard to guess.

Human memory recognition is typically more effective than recall.

Page 4: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

This Paper Analyzes…

Page 5: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

BackgroundGraphical PasswordsVisual MemoryRecognition vs. RecallFace RecognitionPassword Space

Page 6: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Graphical PasswordsDrawmetric schemesLocimetric schemesCognometic schemes

Page 7: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Visual MemoryPictures are recalled and recognized by

human are more easily than words.

Dual-coding theory argues that Memory of images is stronger than memory of words because images are more likely than words to be processed both visually and verbally.

Page 8: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Recognition vs. RecallRecognition occurs when one correctly identifies

someone or something that they already know, when it is presented to them at a later time.

Recall takes place when one thinks back in time and brings to mind information of which one was previously aware.

ExamplePerson’s Face vs. Person’s NameMultiple Choice Questions vs. Essay Question

Page 9: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Face RecognitionThere is an increasing amount of evidence

that there may be regions of the brain dedicated to facial recognition and processing.

ExampleProsopagnosia (face blindness)Visual agnosia (Visual object agnosia)

Page 10: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Password Spacetheoretical password space (all

mathematically possible combinations)effective password space (those combinations

more likely to be chosen by user)

Page 11: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Password Space(Cont.)

Page 12: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Password Space(Cont.)theoretical password space = effective

password space

Page 13: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

First StudyDesign

faces, everyday objects, houses.6 panels of 26 images (28 bits)60 participants (between-subjects)Their age ranged from 18 to 43 (M=21.1,

SD=4.42)

Page 14: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

First Study(Cont.)Authentication system

Page 15: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

First Study(Cont.)Execute

Participants were assigned three graphical passwords randomly.

We sent the participants email several times over the course of a week, asking them to log in from home and comment on articles on each of the websites.

If passwords were forgotten they could be reset.Not encouraged to write down password.System logged all password-related activity on

the websites.

Page 16: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Result Number of password remembered

House imagesM=1.15, SD=1.31

Face imagesM=1.90, SD=1.37

Object imagesM=2.35, SD=0.93

Page 17: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Result(Cont.)Mean memory time - the average amount of

time between the first and last successful login. (hours)

Page 18: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Result(Cont.)Average login time

House imagesM=83.06, SD=54.75

Face imagesM=41.45, SD=14.18

Object imagesM=31.03, SD=16.63

Page 19: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

ImplicationsThere was no evidence that face images were

the best image type.

Roughly half of all passwords were forgotten by the end of the one week study.

The cognometric scheme traditionally employs 3 or 4 panels of 9 images and has been shown to be quite usable.

Page 20: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Second StudyDesign(First)

faces, everyday objects, houses.

6 panels of 26 images (28 bits)

60 participants (between-subjects)

Their age ranged from 18 to 43 (M=21.1, SD=4.42)

Design(Second)faces, everyday

objects.

5 panels of 16 images (20 bits)

20 participants (within-subjects)

Age?

Page 21: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

ResultMean Max Memory TimeFace images

M=167.8, SD=51.73Object images

M=168.5, SD=42.79

Page 22: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

Result(Cont.)Successful Login TimeFace images

M=35.96, SD=18.10Object images

M=22.55, SD=10.02

Page 23: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

ImplicationsChanging the password space

Login times were much quicker.95% of the object image passwords and 87% of

the face image passwords assigned in the second study were remembered for the entire week.

17/20 participants indicated a preference for object images, often citing increased distinctiveness as their reason.

Page 24: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

DiscussionObject > Face > HouseObject

shape, size, color, white backgroundstools, toys, food, flowers, stationery items,

furniture, and more.Face

age, race, gender, expression, etc.ExperienceBrief verbalizationLogin time

Page 25: Facing the Facts about Image Type in  Recognition-Based  Graphical Passwords

ConclusionsIt has been suggested that face images are

the ideal image type, but we found no evidence to support that claim.

We may have a special ability to process and memorize faces, this does not necessarily lead to a superior ability.

Random assigned passwords would be preferable.