EconPapers    
Economics at your fingertips  
 

A Model to Improve Security Questions Through Individualized Assistance

Andrew Mangle, Sandip Patel, Sanjay Bapna, XingXing Zu and David Gurzick
Additional contact information
Andrew Mangle: Bowie State University, USA
Sandip Patel: Morgan State University (Retired), USA
Sanjay Bapna: Morgan State University, USA
XingXing Zu: Morgan State University, USA
David Gurzick: Hood College, USA

International Journal of Information Security and Privacy (IJISP), 2021, vol. 15, issue 4, 31-53

Abstract: Security questions are considered a viable alternative for secondary and supplementary authentication. Security questions are susceptible to three types of attacks: blind (brute force), focused guess (statistical), and observation (research/personal). This research outlines how informing users of potential security threats through a security meter may improve security with minimal impact on usability and trust. A security-question authentication model is proposed that builds on the strengths of security question responses, chiefly their ease of recall and higher entropy, while mitigating the core weaknesses of the model, which are the lack of uniform answers and public accessibility to answers. Users that were made aware of the entropy of their responses were more likely to provide stronger responses to the security questions without affecting the repeatability of the responses to the questions but negatively impacting the memorability.

Date: 2021
References: Add references at CitEc
Citations:

Downloads: (external link)
http://services.igi-global.com/resolvedoi/resolve. ... 018/IJISP.2021100103 (application/pdf)

Related works:
This item may be available elsewhere in EconPapers: Search for items with the same title.

Export reference: BibTeX RIS (EndNote, ProCite, RefMan) HTML/Text

Persistent link: https://EconPapers.repec.org/RePEc:igg:jisp00:v:15:y:2021:i:4:p:31-53

Access Statistics for this article

International Journal of Information Security and Privacy (IJISP) is currently edited by Yassine Maleh

More articles in International Journal of Information Security and Privacy (IJISP) from IGI Global
Bibliographic data for series maintained by Journal Editor ().

 
Page updated 2025-03-19
Handle: RePEc:igg:jisp00:v:15:y:2021:i:4:p:31-53