A Data-Driven Password Strength Meter for Cybersecurity Assessment and Enhancement
Moath M. Algharibeh, Ghaith Husari, Sardar Jaf · 2021
Password-based authentication is the most popular authentication mechanism over insecure networks due to its simplicity and convenience. To ensure the security of this authentication mechanism, measuring the strength of users' passwords is a crucial task not only to guide users to create strong passwords but to protect systems from unauthorized access. Password strength meters are usually used for measuring the strength of passwords, often in real-time. However, password strength meters are only helpful if they are accurate. Passwords meters that do not accurately reflect the actual passwords strengths, e.g., providing a high score for a weak password, may misinform users and hinder the overall security of password-based authentication mechanisms. Also, a user-friendly password strength meter is important in guiding users to create a strong password for further authentication. While many password strength meters were proposed in the literature, using the most appropriate password meter remains a difficult process. In this paper, we propose a data-driven password meter. Our system scrapes and collects large datasets to be used to measure the strength of user passwords based on proven password strength policies and we offer a user-friendly mechanism to help users create a strong password. We evaluate our system by measuring the influence of the proposed meter at guiding users to create stronger passwords by tracking their eye movements. We conducted our experiment with a pilot study on a testing web service and monitored the eye movements of 240 participants using an eye-tracking tool. Our results exhibited a significant improvement by influencing users to create stronger passwords, with an average of 110.97 years for password cracking time.