{"id":13268,"date":"2021-12-08T20:32:15","date_gmt":"2021-12-09T01:32:15","guid":{"rendered":"https:\/\/carleton.ca\/scs\/?page_id=13268"},"modified":"2026-06-02T14:59:23","modified_gmt":"2026-06-02T18:59:23","slug":"tr-08-15-on-purely-automated-attacks-and-click-based-graphical-passwords","status":"publish","type":"page","link":"https:\/\/carleton.ca\/scs\/research\/scs-technical-reports\/technical-reports-2008\/tr-08-15-on-purely-automated-attacks-and-click-based-graphical-passwords\/","title":{"rendered":"TR-08-15: On Purely Automated Attacks and Click-Based Graphical Passwords"},"content":{"rendered":"\n<section class=\"w-screen px-6 cu-section cu-section--white ml-offset-center md:px-8 lg:px-14\">\n    <div class=\"space-y-6 cu-max-w-child-5xl  md:space-y-10 cu-prose-first-last\">\n\n            <div class=\"cu-textmedia flex flex-col lg:flex-row mx-auto gap-6 md:gap-10 my-6 md:my-12 first:mt-0 max-w-5xl\">\n        <div class=\"justify-start cu-textmedia-content cu-prose-first-last\" style=\"flex: 0 0 100%;\">\n            <header class=\"font-light prose-xl cu-pageheader md:prose-2xl cu-component-updated cu-prose-first-last\">\n                                    <h1 class=\"cu-prose-first-last font-semibold !mt-2 mb-4 md:mb-6 relative after:absolute after:h-px after:bottom-0 after:bg-cu-red after:left-px text-3xl md:text-4xl lg:text-5xl lg:leading-[3.5rem] pb-5 after:w-10 text-cu-black-700 not-prose\">\n                        TR-08-15: On Purely Automated Attacks and Click-Based Graphical Passwords\n                    <\/h1>\n                \n                                \n                            <\/header>\n\n                    <\/div>\n\n            <\/div>\n\n    <\/div>\n<\/section>\n\n<p>Carleton University<br>\n<a href=\"https:\/\/carleton.ca\/scs\/research\/scs-technical-reports\/technical-reports-2008\/\">Technical Report<\/a> TR-08-15<br>\nJune 20, 2008<\/p>\n\n\n\n<h2 id=\"on-purely-automated-attacks-and-click-based-graphical-passwords\" class=\"wp-block-heading\">On Purely Automated Attacks and Click-Based Graphical Passwords<\/h2>\n\n\n\n<div class=\"tr_t3\">\n<div class=\"tr_t3\">\n<div class=\"tr_t3\">\n<div class=\"tr_t3\">\n<div class=\"tr_t3\">\n<div class=\"tr_t3\">\n<div class=\"tr_t3\">\n<div class=\"tr_t3\">\n<p class=\"tr_t3\">Amirali Salehi-Abari, Julie Thorpe, P.C. van Oorschot<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div>\n<h3>Abstract<\/h3>\n<p>We present and evaluate various methods for purely automated attacks against click-based graphical passwords. Our purely automated methods combine click-order heuristics with focus-of-attention scan-paths generated from Itti et al.&#8217;s (1998) computational model of visual attention. Testing our method against previous work, it results in a significantly better automated attack, guessing 8-15% of passwords for two representative images using dictionaries of less than 2**24.6 entries, and about 16% of passwords on each of these images using dictionaries of less than 2**31.4 entries (where the full password space is 43 bits). Relaxing our click-order pattern substantially increased the efficacy of our attack albeit with larger dictionaries, allowing attacks that guessed 48-54% of passwords in less than 2**35 guesses (compared to previous results of 0.9% and 9.1% on the same two images with 2**35 guesses). These latter automated attacks are independent of focus-of-attention models, and in fact are based on image-independent guessing patterns. Our results show that automated attacks, which are easier to launch than human-seeded attacks and are more scalable to systems that use multiple images, pose a significant threat to PassPoints-style graphical passwords, and offer an effective alternative to human-seeded attacks.<\/p>\n<p><a href=\"https:\/\/carleton.ca\/scs\/wp-content\/uploads\/sites\/260\/TR-08-15-Van-Oorschot-Thorpe-SalehiAbari.pdf\">TR-08-15.pdf<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Carleton University Technical Report TR-08-15 June 20, 2008 On Purely Automated Attacks and Click-Based Graphical Passwords Amirali Salehi-Abari, Julie Thorpe, P.C. van Oorschot Abstract We present and evaluate various methods for purely automated attacks against click-based graphical passwords. Our purely automated methods combine click-order heuristics with focus-of-attention scan-paths generated from Itti et al.&#8217;s (1998) computational [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":12410,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"_cu_dining_location_slug":"","footnotes":"","_links_to":"","_links_to_target":""},"cu_page_type":[],"class_list":["post-13268","page","type-page","status-publish","hentry"],"acf":{"cu_post_thumbnail":false},"_links":{"self":[{"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/pages\/13268","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/comments?post=13268"}],"version-history":[{"count":2,"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/pages\/13268\/revisions"}],"predecessor-version":[{"id":13270,"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/pages\/13268\/revisions\/13270"}],"up":[{"embeddable":true,"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/pages\/12410"}],"wp:attachment":[{"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/media?parent=13268"}],"wp:term":[{"taxonomy":"cu_page_type","embeddable":true,"href":"https:\/\/carleton.ca\/scs\/wp-json\/wp\/v2\/cu_page_type?post=13268"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}