Full text

Journal of Information Systems Security
Volume 14, Number 1 (2018)
Pages 3146
ISSN 1551-0123 (Print)
ISSN 1551-0808 (Online)
Joakim Kävrestad — University of Skövde, Sweden
Fredrik Eriksson — University of Skövde, Sweden
Marcus Nohlberg — University of Skövde, Sweden
Information Institute Publishing, Washington DC, USA




In order to ensure that we are the only ones that can access our data, we use authentication to secure our computers and different online accounts. Passwords remain the most common type of authentication, even if there are several different ways to authenticate, including biometrics and tokens. With this study we aim to reveal and collect the different strategies that users are using when designing their passwords. To achieve this, a model was developed using interactive interviews with computer forensic experts. The model was then applied on 5,000 passwords gathered from 50 different password databases that had leaked to the Internet. The result is a model that can be used to classify passwords based on the strategy used to create them. As such, the results of this study increase the understanding of passwords and they can be used as a tool in education and training, as well as in future research.




Passwords, Categorization, Classification, Strategies, Model




