A comprehensive simulation tool for the analysis of password policies

  • Authors:
  • Richard Shay;Elisa Bertino

  • Affiliations:
  • 02062, Norwood, MA, USA;Purdue University, Department of Computer Sciences, 305 N. University Street, 47907-2107, West Lafayette, IN, USA

  • Venue:
  • International Journal of Information Security
  • Year:
  • 2009

Quantified Score

Hi-index 0.00

Visualization

Abstract

Modern organizations rely on passwords for preventing illicit access to valuable data and resources. A well designed password policy helps users create and manage more effective passwords. This paper offers a novel model and tool for understanding, creating, and testing password policies. We present a password policy simulation model which incorporates such factors as simulated users, accounts, and services. This model and its implementation enable administrators responsible for creating and managing password policies to test them before giving them to actual users. It also allows researchers to test how different password policy factors impact security, without the time and expense of actual human studies. We begin by presenting our password policy simulation model. We next discuss prior work and validate the model by showing how it is consistent with previous research conducted on human users. We then present and discuss experimental results derived using the model.