Pushing on String: The 'Don't Care' Region of Password Strength.

The article discusses the efficacy of methods for defending password-protected networks from guessing attacks, including enterprises that impose stringent password-composition policies. Topics include research suggesting that stringent passwords do not always reduce the likelihood of successful gues...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 59; no. 11; pp. 66 - 75
Autores principales: FLORÊNCIO, DINEI, HERLEY, CORMAC, VAN OORSCHOT, PAUL C.
Formato: Artículo
Publicado: Association for Computing Machinery Nov2016
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=119379443&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 119379443
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Nov2016
      vid: 59
      iid: 11
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        119379443
        10.1145/2934663
      ppf: 66
      ppct: 9
      formats:
      tig:
        atl: Pushing on String: The 'Don't Care' Region of Password Strength.
      aug:
        au:
          FLORÊNCIO, DINEI
          HERLEY, CORMAC
          VAN OORSCHOT, PAUL C.
        affil:
          Senior researcher in the Multimedia and Interactive Experiences group of Microsoft Research, Redmond, WA
          Principal researcher at Microsoft Research, Redmond, WA
          Professor of computer science and Canada Research Chair in Authentication and Computer Security at Carleton University, Ottawa, Canada
      su:
        Computer password security
        Computer security
        Cyberterrorism
        Counterterrorism
        Phishing
        Computer security vulnerabilities
      sug:
        subj:
          Computer password security
          Computer security
          Cyberterrorism
          Counterterrorism
          Phishing
          Computer security vulnerabilities
      ab: The article discusses the efficacy of methods for defending password-protected networks from guessing attacks, including enterprises that impose stringent password-composition policies. Topics include research suggesting that stringent passwords do not always reduce the likelihood of successful guessing attacks, the use of phishing email messages once an attacker has access to an internal account, and differences in the password strength required to resist online and offline guessing attacks.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2016
    holdings:
      @attributes:
        islocal: N