Usable Security

Human is known for long time as "the weakest link" in computer security systems. Prevalence of social engineering attacks like phishing in recent years is echoing this old principle. Because of this, usable security has been emerging as a new hot research topic in computer security. Most computer security systems involve multimedia data or interface, and some base their security on the use of multimedia technologies for security purposes. Two typical examples are graphical passwords and CAPTCHAs. Yet another example is the use of audio or biometrics for online banking security. The Multimedia Security and Forensics group is also involved in research on the interplay between usable security and multimedia as a natural extension of the core research on multimedia security.

There are several different research topics that are currently carried out by the group, which covers many different ways of how multimedia computing penetrates into computer security (and vice versa). Some research topics are more about the use of multimedia data (image, video, audio, 3-D models, etc.) in computer security systems. Some other research topics are about methods that can improve presentation, analysis and management of computer security systems. Some completed, ongoing and planned projects in this research theme include:

  • Security and usability evaluation of CAPTCHAs: security analysis of text/image/video CAPTCHAs, a reconfigurable automatic security-usability evaluation framework called Captchæcker, combination of CAPTCHAs with other computer security systems.
  • User authentication: new design of graphical password schemes, security and usability analysis of existing graphical password schemes, password visualization, user authentication systems against observer attacks (and their graphical implementations, e.g. SecHCI).
  • E-banking security: human-computer interface offering a better balance between security and usability for e-banking (e.g. low-cost hardware e-banking solution hPIN/hTAN), security analysis of e-banking CAPTCHAs,
    anti-phishing solutions, comparative study on how new technologies are selected, deployed, used, understood, managed, communicated and maintained by both financial institutions and their customers.