Login | Register

A Comprehensive Analysis of Security Questions in Web Authentication

Title:

A Comprehensive Analysis of Security Questions in Web Authentication

Sun, Xin (2024) A Comprehensive Analysis of Security Questions in Web Authentication. Masters thesis, Concordia University.

[thumbnail of PDF file]
Text (PDF file) (application/pdf)
Sun_MASc_F2024.pdf - Accepted Version
Restricted to Repository staff only until 1 January 2026.
Available under License Spectrum Terms of Access.
5MB

Abstract

With the growing prevalence and sophistication of Internet services, user account security has become a critical concern. Security questions, widely adopted as a secondary authentication method, play a pivotal role in various online services. Although research on security questions has a long history, key gaps remain, particularly concerning user perceptions about security questions and the requirements used by websites for selecting and answering security questions. In this thesis, we address these gaps through a two-part study: (1) a comprehensive user survey (N = 292) that captures insights from a diverse and largely representative sample of the US population and (2) an analysis of an extensive set of 26 security requirements across 73 websites, also aiming to uncover security practices and weaknesses in their authentication systems (i.e., answer length restrictions). Additionally, we gather and analyze common online security questions (totaling 1913 questions) across several dimensions, including memorability, consistency, applicability, confidentiality, and specificity.

Our findings reveal previously unreported user misconceptions, such as users' believing that websites already possess correct answers to personal security questions. We also find that many websites allow insecure practices, such as accepting single-character, offering limited question choices, or identical answers for multiple security questions. By addressing both user perceptions and website security requirements, we provide a comprehensive understanding of the weaknesses in current security question practices and contribute to the discourse on improving authentication methods.

Divisions:Concordia University > Gina Cody School of Engineering and Computer Science > Concordia Institute for Information Systems Engineering
Item Type:Thesis (Masters)
Authors:Sun, Xin
Institution:Concordia University
Degree Name:M.A. Sc.
Program:Information Systems Security
Date:4 December 2024
Thesis Supervisor(s):Mannan, Mohammad and Youssef, Amr
ID Code:994852
Deposited By: Xin Sun
Deposited On:17 Jun 2025 17:26
Last Modified:17 Jun 2025 17:26
All items in Spectrum are protected by copyright, with all rights reserved. The use of items is governed by Spectrum's terms of access.

Repository Staff Only: item control page

Downloads per month over past year

Research related to the current document (at the CORE website)
- Research related to the current document (at the CORE website)
Back to top Back to top