Title :
Guessing click-based graphical passwords by eye tracking
Author :
LeBlanc, Daniel ; Forget, Alain ; Biddle, Robert
Author_Institution :
Dept. of Psychol., Carleton Univ., Ottawa, ON, Canada
Abstract :
Click-based graphical passwords are a new method of authentication where passwords are created and entered by clicking in particular places on an image. This paper presents a study that investigated eye tracking as a potential threat to the security of such passwords. If the gaze data from people looking at an image resembles the click-points of other people´s passwords, then covert eye tracking might be used to create dictionaries to effectively guess passwords. The study used an eye tracker to record the participants´ gaze as they looked at images that had been used as the basis for passwords in an earlier study. We then compared the eye tracker data with the actual password click-points gathered during the earlier study, and conducted several forms of analysis to determine the likely success of guessing passwords. The eye tracker data did somewhat resemble the password click-points, and might offer attackers an advantage over guessing at random. The effectiveness shown for this approach was limited, however, although might allow improvement that would result in greater danger, especially if gaze data could be gathered without explicit interaction.
Keywords :
eye; message authentication; authentication; click-based graphical passwords; eye tracker; eye tracking; Calibration; Dictionaries; Heating; Image color analysis; Monte Carlo methods; Pixel; Visualization;
Conference_Titel :
Privacy Security and Trust (PST), 2010 Eighth Annual International Conference on
Conference_Location :
Ottawa, ON
Print_ISBN :
978-1-4244-7551-3
Electronic_ISBN :
978-1-4244-7549-0
DOI :
10.1109/PST.2010.5593249