A Survey: Security Vulnerabilities and Protective Strategies for Graphical Passwords

被引:3
作者
Saadi, Zena Mohammad [1 ]
Sadiq, Ahmed T. [1 ]
Akif, Omar Z. [2 ]
Farhan, Alaa K. [1 ]
机构
[1] Univ Technol Iraq, Comp Sci Dept, Baghdad 10066, Iraq
[2] Univ Baghdad, Coll Educ Pure Sci Ibn Al Haitham, Dept Comp Sci, Baghdad 10066, Iraq
关键词
graphical user authentication; graphical password; possible attacks; security vulnerabilities; countermeasures; SCHEME; MODEL;
D O I
10.3390/electronics13153042
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As technology advances and develops, the need for strong and simple authentication mechanisms that can help protect data intensifies. The contemporary approach to giving access control is through graphical passwords comprising images, patterns, or graphical items. The objective of this review was to determine the documented security risks that are related to the use of graphical passwords, together with the measures that have been taken to prevent them. The review was intended to present an extensive literature review of the subject matter on graphical password protection and to point toward potential future research directions. Many attacks, such as shoulder surfing attacks, SQL injection attacks, and spyware attacks, can easily exploit the graphical password scheme, which is one of the most widely used. To counter these security threats, several measures have been suggested, but none of the security attacks can be completely overcome. Each of the proposed measures has its pros and cons. This study begins by elucidating some of the graphical password schemes studied between 2012 and 2023, delving into potential threats and defense mechanisms associated with these schemes. Following a thorough identification and selection process, five of the reviewed papers explain the threat of shoulder surfing and spyware attacks on graphical password schemes, while two explain the threat of brute force attacks. One paper focuses on dictionary attacks, while four other papers address social engineering, SQL injection attacks, and guessing attacks as potential threats to graphical password schemes. In addition, the papers recognize other forms of attacks, such as video recording attacks, filtering attacks, reverse engineering attacks, multiple observation attacks, key/mouse logger attacks, insider attacks, computer vision attacks, image gallery attacks, sonar attacks, reply attacks, data interception attacks, and histogram manipulation attacks. These attacks are examined in three, three, eight, one, four, one, one, one, one, one, one, and one papers, respectively. Moreover, out of all such countermeasures, most of them are based on three categories-randomization, obfuscation, and password space complexity-which are the most commonly employed strategies for improving graphical password schemes.
引用
收藏
页数:30
相关论文
共 62 条
[1]  
Abass IAM, 2022, INT J ADV COMPUT SC, V13, P490
[2]  
Abbas S.F., 2024, Iraqi J. Inf. Commun. Technol, V6, P28, DOI [10.31987/ijict.6.1.212, DOI 10.31987/IJICT.6.1.212]
[3]  
Abdalkareem Zahraa A., 2021, Journal of Physics: Conference Series, V1755, DOI 10.1088/1742-6596/1755/1/012021
[4]   Systemic Literature Review of Recognition-Based Authentication Method Resistivity to Shoulder-Surfing Attacks [J].
Adebimpe, Lateef Adekunle ;
Ng, Ian Ouii ;
Idris, Mohd Yamani Idna ;
Okmi, Mohammed ;
Ku, Chin Soon ;
Ang, Tan Fong ;
Por, Lip Yee .
APPLIED SCIENCES-BASEL, 2023, 13 (18)
[5]   Replay-Attack Detection and Prevention Mechanism in Industry 4.0 Landscape for Secure SECS/GEM Communications [J].
Al-Shareeda, Mahmood A. A. ;
Manickam, Selvakumar ;
Laghari, Shams A. A. ;
Jaisan, Ashish .
SUSTAINABILITY, 2022, 14 (23)
[6]   Secure Graphical One Time Password (GOTPass): An Empirical Study [J].
Alsaiari, H. ;
Papadaki, M. ;
Dowland, P. ;
Furnell, S. .
INFORMATION SECURITY JOURNAL, 2015, 24 (4-6) :207-220
[7]  
Alsobhi H., 2020, 2020 INT C COMPUTING, DOI [DOI 10.1109/ICCIT-144147971.2020.9213748, 10.1109/iccit-144147971.2020.9213748]
[8]  
[Anonymous], 2012, P MULT SEC MM SEC 12, DOI [DOI 10.1145/2361407.2361424, 10.1145/2361407.2361424, 10.1145/2361407]
[9]  
Assudani P.J., 2018, Int. J. Adv. Res. Comput. Sci, V9, P467, DOI [10.26483/ijarcs.v9i2.5761, DOI 10.26483/IJARCS.V9I2.5761]
[10]   VAP code: A secure graphical password for smart devices [J].
Azad, Saiful ;
Rahman, Musfiq ;
Ranak, M. S. A. Noman ;
Ruhee, B. M. F. Kamal ;
Nisa, N. Nourin ;
Kabir, Nazrul ;
Rahman, Arafatur ;
Zain, Jasni Mohamad .
COMPUTERS & ELECTRICAL ENGINEERING, 2017, 59 :99-109