{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,25]],"date-time":"2025-03-25T14:36:46Z","timestamp":1742913406515,"version":"3.40.3"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031790065"},{"type":"electronic","value":"9783031790072"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-79007-2_2","type":"book-chapter","created":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T20:01:17Z","timestamp":1738094477000},"page":"22-41","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Towards Exploring Cross-Regional and\u00a0Cross-Platform Differences in\u00a0Login Throttling"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-3452-7292","authenticated-orcid":false,"given":"Minjie","family":"Cai","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2664-3963","authenticated-orcid":false,"given":"Xavier","family":"de Carn\u00e9 de Carnavalet","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-4490-8671","authenticated-orcid":false,"given":"Siqi","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6376-4062","authenticated-orcid":false,"given":"Lianying","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7457-5198","authenticated-orcid":false,"given":"Mengyuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,1,29]]},"reference":[{"issue":"1","key":"2_CR1","doi-asserted-by":"publisher","first-page":"57","DOI":"10.1109\/TBIOM.2021.3112540","volume":"4","author":"A Acien","year":"2022","unstructured":"Acien, A., Morales, A., Monaco, J.V., Vera-Rodriguez, R., Fierrez, J.: Typenet: deep learning keystroke biometrics. IEEE Trans. Biometrics Behav. Identity Sci. 4(1), 57\u201370 (2022)","journal-title":"IEEE Trans. Biometrics Behav. Identity Sci."},{"key":"2_CR2","unstructured":"AndroidRank.com: List of Android most popular Google Play apps. https:\/\/www.androidrank.org\/android-most-popular-google-play-apps?start=1&sort=4 &price=all &category=all. Accessed 05 Jan 2024"},{"key":"2_CR3","unstructured":"Awati, R.: TechTarget: risk-based authentication (RBA). https:\/\/www.techtarget.com\/searchsecurity\/definition\/risk-based-authentication-RBA"},{"key":"2_CR4","unstructured":"AZcaptchas: Auto Captcha Solver Service and Cheap Captcha Bypass Service Provider - AZcaptchas. https:\/\/azcaptcha.com\/. Accessed 08 Jan 2024"},{"key":"2_CR5","unstructured":"Bonneau, J., Preibusch, S.: The password thicket: technical and market failures in human authentication on the web. In: Workshop on the Economics of Information Security (2010)"},{"key":"2_CR6","unstructured":"Cloudflare: What is rate limiting? https:\/\/www.cloudflare.com\/en-gb\/learning\/bots\/what-is-rate-limiting\/. Accessed 05 Jan 2024"},{"key":"2_CR7","unstructured":"Flor\u00eancio, D., Herley, C., van Oorschot, P.C.: An administrator\u2019s guide to internet password research. In: Large Installation System Administration Conference (LISA) (2014)"},{"key":"2_CR8","doi-asserted-by":"crossref","unstructured":"Freeman, D., Jain, S., D\u00fcrmuth, M., Biggio, B., Giacinto, G.: Who are you? A statistical approach to measuring user authenticity. In: Network and Distributed System Security Symposium. The Internet Society, San Diego, California (2016)","DOI":"10.14722\/ndss.2016.23240"},{"issue":"3","key":"2_CR9","doi-asserted-by":"publisher","first-page":"42","DOI":"10.1109\/MIC.2013.28","volume":"17","author":"K Fu","year":"2013","unstructured":"Fu, K., Chan, C., Chau, M.: Assessing censorship on microblogs in China: discriminatory keyword analysis and the real-name registration policy. IEEE Internet Comput. 17(3), 42\u201350 (2013)","journal-title":"IEEE Internet Comput."},{"key":"2_CR10","doi-asserted-by":"publisher","first-page":"207","DOI":"10.28945\/3612","volume":"12","author":"R Gafni","year":"2016","unstructured":"Gafni, R., Nagar, I.: Captcha: impact on user experience of users with learning disabilities. Interdisc. J. e-Skills Lifelong Learn. 12, 207\u2013223 (2016)","journal-title":"Interdisc. J. e-Skills Lifelong Learn."},{"key":"2_CR11","unstructured":"Golla, M., Schnitzler, T., D\u00fcrmuth, M., G\u00f6rtz, H.: \u201cWill any password do?\u201d Exploring rate-limiting on the web. In: Who Are You?! Adventures in Authentication (WAY) (2016)"},{"issue":"2","key":"2_CR12","doi-asserted-by":"publisher","first-page":"258","DOI":"10.1109\/TIFS.2015.2490620","volume":"11","author":"W Han","year":"2016","unstructured":"Han, W., Li, Z., Yuan, L., Xu, W.: Regional patterns and vulnerability analysis of Chinese web passwords. IEEE Trans. Inf. Forensics Secur. 11(2), 258\u2013272 (2016)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"2_CR13","unstructured":"Hunt, T.: Pwned passwords, version 6. https:\/\/www.troyhunt.com\/pwned-passwords-version-6\/. Accessed 06 Jan 2024"},{"key":"2_CR14","unstructured":"Hurka\u0142a, A., Hurka\u0142a, J.: Architecture of context-risk-aware authentication system for web environments. In: The Third International Conference on Informatics Engineering and Information Science (2014)"},{"key":"2_CR15","doi-asserted-by":"crossref","unstructured":"Iliou, C., Kostoulas, T., Tsikrika, T., Katos, V., Vrochidis, S., Kompatsiaris, I.: Detection of advanced web bots by combining web logs with mouse behavioural biometrics. Digit. Threats 2(3) (2021)","DOI":"10.1145\/3447815"},{"key":"2_CR16","doi-asserted-by":"crossref","unstructured":"Khattak, S., et al.: Do you see what I see? Differential treatment of anonymous users. In: Annual Network and Distributed System Security Symposium (2016)","DOI":"10.14722\/ndss.2016.23342"},{"issue":"9","key":"2_CR17","first-page":"16","volume":"20","author":"N Kheshaifaty","year":"2020","unstructured":"Kheshaifaty, N., Gutub, A.A.A.: Preventing multiple accessing attacks via efficient integration of CAPTCHA crypto hash functions. Int. J. Comput. Sci. Netw. Secur. 20(9), 16\u201328 (2020)","journal-title":"Int. J. Comput. Sci. Netw. Secur."},{"key":"2_CR18","doi-asserted-by":"crossref","unstructured":"Laperdrix, P., Bielova, N., Baudry, B., Avoine, G.: Browser fingerprinting: a survey. ACM Trans. Web 14(2), 8:1\u20138:33 (2020)","DOI":"10.1145\/3386040"},{"key":"2_CR19","first-page":"1","volume":"25","author":"JA Lee","year":"2016","unstructured":"Lee, J.A., Liu, C.Y.: Real-name registration rules and the fading digital anonymity in China. Washington Int. Law J. 25, 1 (2016)","journal-title":"Washington Int. Law J."},{"key":"2_CR20","unstructured":"Lee, K., Kaiser, B., Mayer, J.R., Narayanan, A.: An empirical study of wireless carrier authentication for SIM swaps. In: Symposium on Usable Privacy and Security (SOUPS), pp. 61\u201379 (2020)"},{"key":"2_CR21","unstructured":"Li, Z., Han, W., Xu, W.: A large-scale empirical analysis of Chinese web passwords. In: USENIX Security (2014)"},{"key":"2_CR22","unstructured":"Liu, X.: Jifeng Forum was exposed to have leaked the information of 23 million users (translated), Beijing News article (2015). https:\/\/www.bjnews.com.cn\/detail\/155148659914920.html. Accessed 01 June 2024"},{"key":"2_CR23","doi-asserted-by":"crossref","unstructured":"Lu, B., Zhang, X., Ling, Z., Zhang, Y., Lin, Z.: A measurement study of authentication rate-limiting mechanisms of modern websites. In: Annual Computer Security Applications Conference (ACSAC) (2018)","DOI":"10.1145\/3274694.3274714"},{"issue":"3","key":"2_CR24","doi-asserted-by":"publisher","first-page":"811","DOI":"10.1287\/isre.2022.1156","volume":"34","author":"S Mao","year":"2023","unstructured":"Mao, S., Dewan, S., Ho, Y.I.: Personalized ranking at a mobile app distribution platform. Inf. Syst. Res. 34(3), 811\u2013827 (2023)","journal-title":"Inf. Syst. Res."},{"key":"2_CR25","unstructured":"Markert, P., Schnitzler, T., Golla, M., D\u00fcrmuth, M.: \u201cAs soon as it\u2019s a risk, I want to require MFA\u201d: how administrators configure risk-based authentication. In: Symposium on Usable Privacy and Security (SOUPS) (2022)"},{"key":"2_CR26","unstructured":"National Institute of Standards and Technology: Digital identity guidelines: Authentication and lifecycle management, NIST Special Publication 800-63B"},{"key":"2_CR27","unstructured":"OpenWall.com: John the Ripper password cracker. https:\/\/www.openwall.com\/john\/. Accessed 05 Jan 2024"},{"key":"2_CR28","unstructured":"Oracle: Oracle: Java card technology. https:\/\/www.oracle.com\/java\/java-card\/"},{"key":"2_CR29","doi-asserted-by":"crossref","unstructured":"Pal, B., Daniel, T., Chatterjee, R., Ristenpart, T.: Beyond credential stuffing: password similarity models using neural networks. In: IEEE Symposium on Security and Privacy (S &P) (2019)","DOI":"10.1109\/SP.2019.00056"},{"key":"2_CR30","doi-asserted-by":"crossref","unstructured":"Rescorla, E.: The transport layer security (TLS) protocol version 1.3. RFC 8446, 1\u2013160 (2018)","DOI":"10.17487\/RFC8446"},{"key":"2_CR31","unstructured":"Sami Laine: SMS two-factor authentication - worse than just a good password?. https:\/\/sec.okta.com\/articles\/2020\/05\/sms-two-factor-authentication-worse-just-good-password"},{"key":"2_CR32","unstructured":"Searles, A., Nakatsuka, Y., Ozturk, E., Paverd, A., Tsudik, G., Enkoji, A.: An empirical study & evaluation of modern captchas. In: USENIX Security (2023)"},{"key":"2_CR33","doi-asserted-by":"crossref","unstructured":"Shahin, M., Zahedi, M., Khalajzadeh, H., Nasab, A.R.: A study of gender discussions in mobile apps. In: International Conference on Mining Software Repositories (2023)","DOI":"10.1109\/MSR59073.2023.00086"},{"key":"2_CR34","unstructured":"Tencent: Tencent official website. https:\/\/sj.qq.com\/. Accessed 06 Jan 2024"},{"key":"2_CR35","unstructured":"Thanh, D.V., J\u00f8rstad, I., J\u00f8nvik, T.E., van Thuan, D.: Strong authentication with mobile phone as security token. In: International Conference on Mobile Adhoc and Sensor Systems (MASS) (2009)"},{"key":"2_CR36","doi-asserted-by":"crossref","unstructured":"Thomas, K., et\u00a0al.: Data breaches, phishing, or malware? Understanding the risks of stolen credentials. In: ACM Conference on Computer and Communications Security (2017)","DOI":"10.1145\/3133956.3134067"},{"key":"2_CR37","unstructured":"Wang, D., Wang, P., He, D., Tian, Y.: Birthday, name and bifacial-security: understanding passwords of Chinese web users. In: USENIX Security (2019)"},{"key":"2_CR38","doi-asserted-by":"crossref","unstructured":"Wang, D., Zhang, Z., Wang, P., Yan, J., Huang, X.: Targeted online password guessing: an underestimated threat. In: ACM Conference on Computer and Communications Security (2016)","DOI":"10.1145\/2976749.2978339"},{"issue":"1","key":"2_CR39","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1177\/0018720821998110","volume":"65","author":"X Wang","year":"2023","unstructured":"Wang, X., Markert, C., Sasangohar, F.: Investigating popular mental health mobile application downloads and activity during the COVID-19 pandemic. Hum. Factors 65(1), 50\u201361 (2023)","journal-title":"Hum. Factors"},{"key":"2_CR40","doi-asserted-by":"crossref","unstructured":"Wentz, B., Pham, D.J., Tressler, K.: Exploring the accessibility of banking and finance systems for blind users. First Monday 22(3) (2017)","DOI":"10.5210\/fm.v22i3.7036"},{"key":"2_CR41","unstructured":"Wiefling, S., Iacono, L.L., D\u00fcrmuth, M.: Is this really you? An empirical study on risk-based authentication applied in the wild. CoRR abs\/2003.07622 (2020)"},{"key":"2_CR42","unstructured":"Chen, X., Zhou, Y.: Mobile login methods help Chinese users avoid password roadblocks. https:\/\/www.nngroup.com\/articles\/mobile-login-china\/"}],"container-title":["Lecture Notes in Computer Science","Secure IT Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-79007-2_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T20:01:30Z","timestamp":1738094490000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-79007-2_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031790065","9783031790072"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-79007-2_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"29 January 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"NordSec","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nordic Conference on Secure IT Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Karlstad","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sweden","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 November 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 November 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nordsec2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/nordsec2024.kau.se\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}