论文标题

孟加拉国政府网站中密码安全因素的研究

A Study of Password Security Factors among Bangladeshi Government Websites

论文作者

Chowdhury, Adil Ahmed, Chowdhury, Farida, Ferdous, Md Sadek

论文摘要

孟加拉国政府通过通过许多网站将公共服务转变为在线服务,积极地改变其公共服务格局。动机是,这将是公民生活各个方面变革的催化剂。为此,某些Web服务必须受到任何未经授权的用法的保护,并且密码仍然是最广泛使用的凭证机制。但是,如果未正确采用密码,则可能是安全漏洞的原因。这就是为什么在不同网站上研究密码安全的不同方面很重要的原因。在本文中,我们介绍了36个不同的孟加拉国政府网站中密码安全性的研究,该网站涉及6个精心选择的密码安全启发式方法。这项研究是该领域中的第一个研究,并提供了有趣的见解。例如,许多网站尚未采用有关安全性的适当安全措施。许多网站都没有采用密码构建指南,因此为用户创造了一个障碍,以选择强密码。其中一些允许较弱的密码,但仍然没有使用安全的HTTPS频道通过Internet传输信息。

The Government of Bangladesh is aggressively transforming its public service landscape by transforming public services into online services via a number of websites. The motivation is that this would be a catalyst for a transformative change in every aspect of citizen life. Some web services must be protected from any unauthorised usages and passwords remain the most widely used credential mechanism for this purpose. However, if passwords are not adopted properly, they can be a cause for security breach. That is why it is important to study different aspects of password security on different websites. In this paper, we present a study of password security among 36 different Bangladeshi government websites against six carefully chosen password security heuristics. This study is the first of its kind in this domain and offers interesting insights. For example, many websites have not adopted proper security measures with respect to security. There is no password construction guideline adopted by many websites, thus creating a barrier for users to select a strong password. Some of them allow supposedly weak passwords and still do not utilise a secure HTTPS channel to transmit information over the Internet.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源