TY - JOUR
T1 - Forcing Johnny to login safely
AU - Herzberg, Amir
AU - Margulies, Ronen
PY - 2013
Y1 - 2013
N2 - We present the results of the first long-term user study of site-based login mechanisms which force and train users to login safely. We found that interactive site-identifying images received 70% detection rates, which is significantly better than the results received by the typical login ceremony and with passive defense indicators [in: CHI'06: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, ACM, New York, 2006, pp. 601-610; Computers & Security 28(1,2) (2009), 63-71; in: SP'07: Proceedings of the 2007 IEEE Symposium on Security and Privacy, IEEE Computer Society, Washington, 2007, pp. 51-65]. We also found that combining login bookmarks with interactive images and 'non-working' buttons/links achieved the best detection rates (82%) and overall resistance rates (93%). We also present WAPP (Web Application Phishing-Protection), an effective server-side solution which combines the login bookmark and the interactive custom image indicators. WAPP provides two-factor and two-sided authentication.
AB - We present the results of the first long-term user study of site-based login mechanisms which force and train users to login safely. We found that interactive site-identifying images received 70% detection rates, which is significantly better than the results received by the typical login ceremony and with passive defense indicators [in: CHI'06: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, ACM, New York, 2006, pp. 601-610; Computers & Security 28(1,2) (2009), 63-71; in: SP'07: Proceedings of the 2007 IEEE Symposium on Security and Privacy, IEEE Computer Society, Washington, 2007, pp. 51-65]. We also found that combining login bookmarks with interactive images and 'non-working' buttons/links achieved the best detection rates (82%) and overall resistance rates (93%). We also present WAPP (Web Application Phishing-Protection), an effective server-side solution which combines the login bookmark and the interactive custom image indicators. WAPP provides two-factor and two-sided authentication.
KW - Phishing
KW - forcing functions
KW - human factors
KW - long-term user study
KW - training
UR - http://www.scopus.com/inward/record.url?scp=84881473914&partnerID=8YFLogxK
U2 - 10.3233/jcs-130467
DO - 10.3233/jcs-130467
M3 - ???researchoutput.researchoutputtypes.contributiontojournal.article???
AN - SCOPUS:84881473914
SN - 0926-227X
VL - 21
SP - 393
EP - 424
JO - Journal of Computer Security
JF - Journal of Computer Security
IS - 3
ER -