ACM Home Page
Please provide us with feedback. Feedback
Securing passwords against dictionary attacks
Full text PdfPdf (217 KB)
Source Conference on Computer and Communications Security archive
Proceedings of the 9th ACM conference on Computer and communications security table of contents
Washington, DC, USA
SESSION: Authentication and authorization table of contents
Pages: 161 - 170  
Year of Publication: 2002
ISBN:1-58113-612-9
Authors
Benny Pinkas  HP Labs
Tomas Sander  HP Labs
Sponsors
ACM: Association for Computing Machinery
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 39,   Downloads (12 Months): 262,   Citation Count: 22
Additional Information:

abstract   references   cited by   index terms   collaborative colleagues  

Tools and Actions: Request Permissions Request Permissions    Review this Article  
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/586110.586133
What is a DOI?

ABSTRACT

The use of passwords is a major point of vulnerability in computer security, as passwords are often easy to guess by automated programs running dictionary attacks. Passwords remain the most widely used authentication method despite their well-known security weaknesses. User authentication is clearly a practical problem. From the perspective of a service provider this problem needs to be solved within real-world constraints such as the available hardware and software infrastructures. From a user's perspective user-friendliness is a key requirement.In this paper we suggest a novel authentication scheme that preserves the advantages of conventional password authentication, while simultaneously raising the costs of online dictionary attacks by orders of magnitude. The proposed scheme is easy to implement and overcomes some of the difficulties of previously suggested methods of improving the security of user authentication schemes.Our key idea is to efficiently combine traditional password authentication with a challenge that is very easy to answer by human users, but is (almost) infeasible for automated programs attempting to run dictionary attacks. This is done without affecting the usability of the system. The proposed scheme also provides better protection against denial of service attacks against user accounts.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

 
1
Alta Vista, submission of new urls. http://addurl.altavista.com/sites/addurl/newurl
 
2
 
3
M., Proactive Password Checking, 4th Workshop on Computer Security Incident Handling, August 1992.
 
4
N. Bohm, I. Brown, B. Gladman, Electronic Commerce: Who Carries the Risk of Fraud?, 2000 (3) The Journal of Information, Law and Technology. http://elj.warwick.ac.uk/jilt/00-3/bohm.html
5
 
6
The CAPTCHA Project. http://www.captcha.net/
 
7
The CAPTCHA Project: Gimpy. http://www.captcha.net/gimpy.html
 
8
Hackers find new way to bilk eBay users, CNET news.com, March 25, 2002.
 
9
 
10
K. Fu, E. Sit, K. Smith, and N. Feamster, Dos and Don'ts of Client Authentication on the Web, 10th USENIX Security Symp., August 2001.
 
11
12
 
13
I. Jermyn, A. Mayer, F. Monrose, M.K. Reiter and A.D. Rubin. The design and analysis of graphical passwords. 8th USENIX Security Symp., August 1999.
 
14
M.D. Lillibridge, M. Abadi, K. Bharat, and A.Z. Broder. Method for selectively restricting access to computer systems. U.S. Patent 6,195,698 (2001).
 
15
D.V. Klein, Foiling the Cracker: A Survey of, and Improvements to, Password Security, 2nd USENIX Unix Security Workshop, 1990, pp.5--14.
 
16
17
 
18
F. Monrose, M. Reiter and S. Wetzel Password hardening based on keystroke dynamics, to appear in the International Journal of Information Security, Springer, 2002.
19
 
20
M. Naor, Verification of a human in the loop, or Identification via the Turing test, Manuscript (1996). \verb+http://www.wisdom.weizmann.ac.il/naor/PAPERS/+\verb+human_abs.html+
 
21
Paypal, new account reg. http://www.paypal.com.
 
22
J. Xu, R. Lipton, I. Essa, M.-H. Sung, Mandatory human participation: A new scheme for building secure systems, Georgia Institute of Technology Technical Report GIT-CC-01-09, 2001.
 
23
A. Perrig and R, Dhamija, Dj Vu: A User Study Using Images for Authentication, 9th Usenix security Symp., August 2000.
 
24
 
25
Workshop on Human Interactive Proofs http://www.parc.xerox.com/istl/groups/did/HIP2002/
 
26
Yahoo!, new account registration.

CITED BY  22

Collaborative Colleagues:
Benny Pinkas: colleagues
Tomas Sander: colleagues