Home > Research > Publications & Outputs > Shoulder surfing defence for recall-based graph...

Links

Text available via DOI:

View graph of relations

Shoulder surfing defence for recall-based graphical passwords

Research output: Contribution in Book/Report/Proceedings - With ISBN/ISSNConference contribution/Paperpeer-review

Published

Standard

Shoulder surfing defence for recall-based graphical passwords. / Zakaria, Nur Haryani; Griffiths, David; Brostoff, Sacha et al.
SOUPS 2011 - Proceedings of the 7th Symposium on Usable Privacy and Security. New York: ACM, 2011. 6.

Research output: Contribution in Book/Report/Proceedings - With ISBN/ISSNConference contribution/Paperpeer-review

Harvard

Zakaria, NH, Griffiths, D, Brostoff, S & Yan, J 2011, Shoulder surfing defence for recall-based graphical passwords. in SOUPS 2011 - Proceedings of the 7th Symposium on Usable Privacy and Security., 6, ACM, New York, 7th Symposium on Usable Privacy and Security, SOUPS 2011, Pittsburgh, PA, United States, 20/07/11. https://doi.org/10.1145/2078827.2078835

APA

Zakaria, N. H., Griffiths, D., Brostoff, S., & Yan, J. (2011). Shoulder surfing defence for recall-based graphical passwords. In SOUPS 2011 - Proceedings of the 7th Symposium on Usable Privacy and Security Article 6 ACM. https://doi.org/10.1145/2078827.2078835

Vancouver

Zakaria NH, Griffiths D, Brostoff S, Yan J. Shoulder surfing defence for recall-based graphical passwords. In SOUPS 2011 - Proceedings of the 7th Symposium on Usable Privacy and Security. New York: ACM. 2011. 6 doi: 10.1145/2078827.2078835

Author

Zakaria, Nur Haryani ; Griffiths, David ; Brostoff, Sacha et al. / Shoulder surfing defence for recall-based graphical passwords. SOUPS 2011 - Proceedings of the 7th Symposium on Usable Privacy and Security. New York : ACM, 2011.

Bibtex

@inproceedings{6519480df312442283be6eff534dae2b,
title = "Shoulder surfing defence for recall-based graphical passwords",
abstract = "Graphical passwords are often considered prone to shoulder-surfing attacks, where attackers can steal a user's password by peeking over his or her shoulder in the authentication process. In this paper, we explore shoulder surfing defence for recall-based graphical password systems such as Draw-A-Secret and Background Draw-A-Secret, where users doodle their passwords (i.e. secrets) on a drawing grid. We propose three innovative shoulder surfing defence techniques, and conduct two separate controlled laboratory experiments to evaluate both security and usability perspectives of the proposed techniques. One technique was expected to work to some extent theoretically, but it turned out to provide little protection. One technique provided the best overall shoulder surfing defence, but also caused some usability challenges. The other technique achieved reasonable shoulder surfing defence and good usability simultaneously, a good balance which the two other techniques did not achieve. Our results appear to be also relevant to other graphical password systems such as Pass-Go.",
keywords = "graphical passwords, shoulder-surfing defence, usability",
author = "Zakaria, {Nur Haryani} and David Griffiths and Sacha Brostoff and Jeff Yan",
year = "2011",
doi = "10.1145/2078827.2078835",
language = "English",
isbn = "9781450309110",
booktitle = "SOUPS 2011 - Proceedings of the 7th Symposium on Usable Privacy and Security",
publisher = "ACM",
note = "7th Symposium on Usable Privacy and Security, SOUPS 2011 ; Conference date: 20-07-2011 Through 22-07-2011",

}

RIS

TY - GEN

T1 - Shoulder surfing defence for recall-based graphical passwords

AU - Zakaria, Nur Haryani

AU - Griffiths, David

AU - Brostoff, Sacha

AU - Yan, Jeff

PY - 2011

Y1 - 2011

N2 - Graphical passwords are often considered prone to shoulder-surfing attacks, where attackers can steal a user's password by peeking over his or her shoulder in the authentication process. In this paper, we explore shoulder surfing defence for recall-based graphical password systems such as Draw-A-Secret and Background Draw-A-Secret, where users doodle their passwords (i.e. secrets) on a drawing grid. We propose three innovative shoulder surfing defence techniques, and conduct two separate controlled laboratory experiments to evaluate both security and usability perspectives of the proposed techniques. One technique was expected to work to some extent theoretically, but it turned out to provide little protection. One technique provided the best overall shoulder surfing defence, but also caused some usability challenges. The other technique achieved reasonable shoulder surfing defence and good usability simultaneously, a good balance which the two other techniques did not achieve. Our results appear to be also relevant to other graphical password systems such as Pass-Go.

AB - Graphical passwords are often considered prone to shoulder-surfing attacks, where attackers can steal a user's password by peeking over his or her shoulder in the authentication process. In this paper, we explore shoulder surfing defence for recall-based graphical password systems such as Draw-A-Secret and Background Draw-A-Secret, where users doodle their passwords (i.e. secrets) on a drawing grid. We propose three innovative shoulder surfing defence techniques, and conduct two separate controlled laboratory experiments to evaluate both security and usability perspectives of the proposed techniques. One technique was expected to work to some extent theoretically, but it turned out to provide little protection. One technique provided the best overall shoulder surfing defence, but also caused some usability challenges. The other technique achieved reasonable shoulder surfing defence and good usability simultaneously, a good balance which the two other techniques did not achieve. Our results appear to be also relevant to other graphical password systems such as Pass-Go.

KW - graphical passwords

KW - shoulder-surfing defence

KW - usability

U2 - 10.1145/2078827.2078835

DO - 10.1145/2078827.2078835

M3 - Conference contribution/Paper

AN - SCOPUS:84855691831

SN - 9781450309110

BT - SOUPS 2011 - Proceedings of the 7th Symposium on Usable Privacy and Security

PB - ACM

CY - New York

T2 - 7th Symposium on Usable Privacy and Security, SOUPS 2011

Y2 - 20 July 2011 through 22 July 2011

ER -