Title:
A diversity-based framework for dynamic password policy generation

dc.contributor.advisor Beyah, Raheem A.
dc.contributor.author Yang, Shukun
dc.contributor.committeeMember Copeland, John
dc.contributor.committeeMember Owen, Henry
dc.contributor.department Electrical and Computer Engineering
dc.date.accessioned 2017-06-07T17:38:18Z
dc.date.available 2017-06-07T17:38:18Z
dc.date.created 2016-05
dc.date.issued 2016-04-27
dc.date.submitted May 2016
dc.date.updated 2017-06-07T17:38:18Z
dc.description.abstract To keep password users from creating simple and common passwords, major websites and applications provide a password-strength measure, namely a password checker that displays instant password strength ratings in levels e.g., “strong”, “moderate”, and “weak”. While critical requirements for a password checker to be stringent have prevailed in the study of password security, we find that regardless of the stringency, such static checkers can leak information and actually help the adversary enhance the performance of their attacks. To address this weakness, we propose and devise the Dynamic Password Policy Generator, namely DPPG, to be an effective and usable alternative to the existing password strength checker. DPPG aims to enforce an evenly-distributed password space and generate dynamic policies for users to create passwords that are diverse and contribute to the overall security of the password database. Since DPPG is modular and can function with different underlying metrics for policy generation, we further introduce a diversity-based password security metric that evaluates the security of a password database in terms of password space and distribution. The metric is useful as a countermeasure to well-crafted offline cracking algorithms and theoretically illustrates why DPPG works well.
dc.description.degree M.S.
dc.format.mimetype application/pdf
dc.identifier.uri http://hdl.handle.net/1853/58192
dc.language.iso en_US
dc.publisher Georgia Institute of Technology
dc.subject Password
dc.subject Authentication
dc.subject Security
dc.title A diversity-based framework for dynamic password policy generation
dc.type Text
dc.type.genre Thesis
dspace.entity.type Publication
local.contributor.advisor Beyah, Raheem A.
local.contributor.corporatename School of Electrical and Computer Engineering
local.contributor.corporatename College of Engineering
relation.isAdvisorOfPublication 88360599-cf62-474a-81dd-961af8abbb9b
relation.isOrgUnitOfPublication 5b7adef2-447c-4270-b9fc-846bd76f80f2
relation.isOrgUnitOfPublication 7c022d60-21d5-497c-b552-95e489a06569
thesis.degree.level Masters
Files
Original bundle
Now showing 1 - 1 of 1
Thumbnail Image
Name:
YANG-THESIS-2016.pdf
Size:
983.65 KB
Format:
Adobe Portable Document Format
Description:
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
LICENSE.txt
Size:
3.86 KB
Format:
Plain Text
Description: