Forcing Johnny to login safely: Long-term user study of forcing and training login mechanisms

Amir Herzberg, Ronen Margulies

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

11 Scopus citations

Abstract

We present the results of the first long-term user study of site-based login mechanisms which force and train users to login safely. We found that interactive site-identifying images received 70% detection rates, which is significantly better than passive indicators' results [15,8,12]. We also found that login bookmarks, when used together with 'non-working' links, doubled the prevention rates of reaching spoofed login pages in the first place. Combining these mechanism provides effective prevention and detection of phishing attacks, and when several images are displayed in the login page, the best detection rates (82%) and overall resistance rates (93%) are achieved. We also introduce the notion of negative training functions, which train users not to take dangerous actions by experiencing failure when taking them.

Original languageEnglish
Title of host publicationComputer Security, ESORICS 2011 - 16th European Symposium on Research in Computer Security, Proceedings
PublisherSpringer Verlag
Pages452-471
Number of pages20
ISBN (Print)9783642238215
DOIs
StatePublished - 2011
Event16th European Symposium on Research in Computer Security, ESORICS 2011 - Leuven, Belgium
Duration: 12 Sep 201114 Sep 2011

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume6879 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference16th European Symposium on Research in Computer Security, ESORICS 2011
Country/TerritoryBelgium
CityLeuven
Period12/09/1114/09/11

Fingerprint

Dive into the research topics of 'Forcing Johnny to login safely: Long-term user study of forcing and training login mechanisms'. Together they form a unique fingerprint.

Cite this