{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T16:45:19Z","timestamp":1778258719290,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,12,3]],"date-time":"2018-12-03T00:00:00Z","timestamp":1543795200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,12,3]]},"DOI":"10.1145\/3274694.3274714","type":"proceedings-article","created":{"date-parts":[[2018,12,4]],"date-time":"2018-12-04T13:07:01Z","timestamp":1543928821000},"page":"89-100","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["A Measurement Study of Authentication Rate-Limiting Mechanisms of Modern Websites"],"prefix":"10.1145","author":[{"given":"Bo","family":"Lu","sequence":"first","affiliation":[{"name":"The Ohio State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaokuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"The Ohio State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ziman","family":"Ling","sequence":"additional","affiliation":[{"name":"The Ohio State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yinqian","family":"Zhang","sequence":"additional","affiliation":[{"name":"The Ohio State University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiqiang","family":"Lin","sequence":"additional","affiliation":[{"name":"The Ohio State University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,12,3]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Alexa. Top Sites in United States - Alexa. https:\/\/www.alexa.com\/topsites\/countries\/US.  Alexa. Top Sites in United States - Alexa. https:\/\/www.alexa.com\/topsites\/countries\/US."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2011.24"},{"key":"e_1_3_2_1_3_1","volume-title":"Breaking reCAPTCHA: a holistic approach via shape recognition. Future challenges in security and privacy for academia and industry","author":"Baecher Paul","year":"2011","unstructured":"Paul Baecher , Niklas B\u00fcscher , Marc Fischlin , and Benjamin Milde . 2011. Breaking reCAPTCHA: a holistic approach via shape recognition. Future challenges in security and privacy for academia and industry ( 2011 ). Paul Baecher, Niklas B\u00fcscher, Marc Fischlin, and Benjamin Milde. 2011. Breaking reCAPTCHA: a holistic approach via shape recognition. Future challenges in security and privacy for academia and industry (2011)."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-17533-1_18"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_3_2_1_6_1","unstructured":"Joseph Bonneau and S\u00f6ren Preibusch. 2010. The Password Thicket: Technical and Market Failures in Human Authentication on the Web. In WEIS.  Joseph Bonneau and S\u00f6ren Preibusch. 2010. The Password Thicket: Technical and Market Failures in Human Authentication on the Web. In WEIS."},{"key":"e_1_3_2_1_7_1","volume-title":"CHI 2003 Workshop on HCI and Security Systems.","author":"Brostoff Sacha","unstructured":"Sacha Brostoff and M. Angela Sasse . 2003. \"Ten strikes and you're out\": Increasing the number of login attempts can improve password usability . In CHI 2003 Workshop on HCI and Security Systems. Sacha Brostoff and M. Angela Sasse. 2003. \"Ten strikes and you're out\": Increasing the number of login attempts can improve password usability. In CHI 2003 Workshop on HCI and Security Systems."},{"key":"e_1_3_2_1_8_1","volume-title":"Mitchell","author":"Bursztein Elie","year":"2014","unstructured":"Elie Bursztein , Jonathan Aigrain , Angelika Moscicki , and John C . Mitchell . 2014 . The End is Nigh : Generic Solving of Text-based CAPTCHAs.. In 8th USENIX Workshop on Offensive Technologies. USENIX Association . Elie Bursztein, Jonathan Aigrain, Angelika Moscicki, and John C. Mitchell. 2014. The End is Nigh: Generic Solving of Text-based CAPTCHAs.. In 8th USENIX Workshop on Offensive Technologies. USENIX Association."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046724"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/2556288.2557322"},{"key":"e_1_3_2_1_11_1","unstructured":"CAPTCHA. The Official CAPTCHA Site. http:\/\/www.captcha.net.  CAPTCHA. The Official CAPTCHA Site. http:\/\/www.captcha.net."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-31149-9_16"},{"key":"e_1_3_2_1_13_1","volume-title":"The Tangled Web of Password Reuse. In The Network and Distributed System Security Symposium. Internet Society.","author":"Das Anupam","year":"2014","unstructured":"Anupam Das , Joseph Bonneau , Matthew Caesar , Nikita Borisov , and XiaoFeng Wang . 2014 . The Tangled Web of Password Reuse. In The Network and Distributed System Security Symposium. Internet Society. Anupam Das, Joseph Bonneau, Matthew Caesar, Nikita Borisov, and XiaoFeng Wang. 2014. The Tangled Web of Password Reuse. In The Network and Distributed System Security Symposium. Internet Society."},{"key":"e_1_3_2_1_14_1","volume-title":"D\u00e9J\u00e0 Vu: A User Study Using Images for Authentication. In 9th Conference on USENIX Security Symposium. USENIX Association.","author":"Dhamija Rachna","year":"2000","unstructured":"Rachna Dhamija and Adrian Perrig . 2000 . D\u00e9J\u00e0 Vu: A User Study Using Images for Authentication. In 9th Conference on USENIX Security Symposium. USENIX Association. Rachna Dhamija and Adrian Perrig. 2000. D\u00e9J\u00e0 Vu: A User Study Using Images for Authentication. In 9th Conference on USENIX Security Symposium. USENIX Association."},{"key":"e_1_3_2_1_15_1","volume-title":"28th Large Installation System Administration Conference. USENIX Association.","author":"Flor\u00eancio Dinei","unstructured":"Dinei Flor\u00eancio , Cormac Herley , and Paul C . van Oorschot. 2014. An Administrator's Guide to Internet Password Research .. In 28th Large Installation System Administration Conference. USENIX Association. Dinei Flor\u00eancio, Cormac Herley, and Paul C. van Oorschot. 2014. An Administrator's Guide to Internet Password Research.. In 28th Large Installation System Administration Conference. USENIX Association."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2012.08.013"},{"key":"e_1_3_2_1_17_1","unstructured":"Paul A. Grassi Elaine M. Newton Ray A. Perlner Andrew R. Regenscheid James L. Fenton William E. Burr Justin P. Richer Naomi B. Lefkovitz Jamie M. Danker Yee-Yin Choong Kristen K. Greene and Mary F. Theofanos. http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-63b.pdf Title = Digital Identity Guidelines: Authentication and Lifecycle Management.  Paul A. Grassi Elaine M. Newton Ray A. Perlner Andrew R. Regenscheid James L. Fenton William E. Burr Justin P. Richer Naomi B. Lefkovitz Jamie M. Danker Yee-Yin Choong Kristen K. Greene and Mary F. Theofanos. http:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-63b.pdf Title = Digital Identity Guidelines: Authentication and Lifecycle Management."},{"key":"e_1_3_2_1_18_1","volume-title":"Password cracking and countermeasures in computer security: A survey. arXiv preprint arXiv:1411.7803","author":"Han Aaron L-F","year":"2014","unstructured":"Aaron L-F Han , Derek F Wong , and Lidia S Chao . 2014. Password cracking and countermeasures in computer security: A survey. arXiv preprint arXiv:1411.7803 ( 2014 ). Aaron L-F Han, Derek F Wong, and Lidia S Chao. 2014. Password cracking and countermeasures in computer security: A survey. arXiv preprint arXiv:1411.7803 (2014)."},{"key":"e_1_3_2_1_19_1","volume-title":"Passgan: A deep learning approach for password guessing. arXiv preprint arXiv:1709.00440","author":"Hitaj Briland","year":"2017","unstructured":"Briland Hitaj , Paolo Gasti , Giuseppe Ateniese , and Fernando Perez-Cruz . 2017 . Passgan: A deep learning approach for password guessing. arXiv preprint arXiv:1709.00440 (2017). Briland Hitaj, Paolo Gasti, Giuseppe Ateniese, and Fernando Perez-Cruz. 2017. Passgan: A deep learning approach for password guessing. arXiv preprint arXiv:1709.00440 (2017)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/328236.328110"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.38"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1920261.1920288"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2016.7524583"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.50"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516726"},{"key":"e_1_3_2_1_26_1","volume-title":"25th USENIX Security Symposium. USENIX Association.","author":"Melicher William","year":"2016","unstructured":"William Melicher , Blase Ur , Sean M. Segreti , Saranga Komanduri , Lujo Bauer , Nicolas Christin , and Lorrie Faith Cranor . 2016 . Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks . In 25th USENIX Security Symposium. USENIX Association. William Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri, Lujo Bauer, Nicolas Christin, and Lorrie Faith Cranor. 2016. Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks. In 25th USENIX Security Symposium. USENIX Association."},{"key":"e_1_3_2_1_27_1","unstructured":"Microsoft. Microsoft Azure: Cloud Computing Platform & Services. https:\/\/azure.microsoft.com\/.  Microsoft. Microsoft Azure: Cloud Computing Platform & Services. https:\/\/azure.microsoft.com\/."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.14722\/usec.2014.23021"},{"key":"e_1_3_2_1_29_1","volume-title":"USENIX Security Symposium.","author":"Motoyama Marti","year":"2010","unstructured":"Marti Motoyama , Kirill Levchenko , Chris Kanich , Damon McCoy , Geoffrey M Voelker , and Stefan Savage . 2010 . Re: CAPTCHAs-Understanding CAPTCHA-Solving Services in an Economic Context .. In USENIX Security Symposium. Marti Motoyama, Kirill Levchenko, Chris Kanich, Damon McCoy, Geoffrey M Voelker, and Stefan Savage. 2010. Re: CAPTCHAs-Understanding CAPTCHA-Solving Services in an Economic Context.. In USENIX Security Symposium."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102168"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/586110.586133"},{"key":"e_1_3_2_1_32_1","volume-title":"The Network and Distributed System Security Symposium. Internet Society.","author":"Rafael Veras Christopher Collins","year":"2014","unstructured":"Christopher Collins Rafael Veras and Julie Thorpe . 2014 . On the Semantic Patterns of Passwords and their Security Impact . In The Network and Distributed System Security Symposium. Internet Society. Christopher Collins Rafael Veras and Julie Thorpe. 2014. On the Semantic Patterns of Passwords and their Security Impact. In The Network and Distributed System Security Symposium. Internet Society."},{"key":"e_1_3_2_1_33_1","unstructured":"Karen Renaud Rosanne English Thomas Wynne and Florian Weber. 2014. You Have Three Tries Before Lockout. Why Three?.. In HAISA.  Karen Renaud Rosanne English Thomas Wynne and Florian Weber. 2014. You Have Three Tries Before Lockout. Why Three?.. In HAISA."},{"key":"e_1_3_2_1_34_1","unstructured":"Selenium. Selenium - Web Browser Automation. www.seleniumhq.org\/.  Selenium. Selenium - Web Browser Automation. www.seleniumhq.org\/."},{"key":"e_1_3_2_1_35_1","unstructured":"Shadowsocks. Shadowsocks - A secure socks5 proxy. https:\/\/shadowsocks.org\/.  Shadowsocks. Shadowsocks - A secure socks5 proxy. https:\/\/shadowsocks.org\/."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.37"},{"key":"e_1_3_2_1_37_1","unstructured":"Squarespace. Reporting Vulnerabilities. https:\/\/www.squarespace.com\/security.  Squarespace. Reporting Vulnerabilities. https:\/\/www.squarespace.com\/security."},{"key":"e_1_3_2_1_38_1","volume-title":"Measuring Real-World Accuracies and Biases in Modeling Password Guessability. In 24th USENIX Security Symposium. USENIXAssociation.","author":"Ur Blase","year":"2015","unstructured":"Blase Ur , Sean M. Segreti , Lujo Bauer , Nicolas Christin , Lorrie Faith Cranor , Saranga Komanduri , Darya Kurilova , Michelle L. Mazurek , William Melicher , and Richard Shay . 2015 . Measuring Real-World Accuracies and Biases in Modeling Password Guessability. In 24th USENIX Security Symposium. USENIXAssociation. Blase Ur, Sean M. Segreti, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Saranga Komanduri, Darya Kurilova, Michelle L. Mazurek, William Melicher, and Richard Shay. 2015. Measuring Real-World Accuracies and Biases in Modeling Password Guessability. In 24th USENIX Security Symposium. USENIXAssociation."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/1178618.1178619"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"crossref","unstructured":"Rafael Veras Christopher Collins and Julie Thorpe. 2014. On Semantic Patterns of Passwords and their Security Impact.. In NDSS.  Rafael Veras Christopher Collins and Julie Thorpe. 2014. On Semantic Patterns of Passwords and their Security Impact.. In NDSS.","DOI":"10.14722\/ndss.2014.23103"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.5555\/1766171.1766196"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3176258.3176332"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978339"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.8"},{"key":"e_1_3_2_1_45_1","unstructured":"Wikipedia. CAPTCHA-Wikipedia. https:\/\/en.wikipedia.org\/wiki\/CAPTCHA.  Wikipedia. CAPTCHA-Wikipedia. https:\/\/en.wikipedia.org\/wiki\/CAPTCHA."},{"key":"e_1_3_2_1_46_1","unstructured":"Wikipedia. CAPTCHA-Wikipedia:circumvention. https:\/\/en.wikipedia.org\/wiki\/CAPTCHA#circumvention.  Wikipedia. CAPTCHA-Wikipedia:circumvention. https:\/\/en.wikipedia.org\/wiki\/CAPTCHA#circumvention."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866328"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866329"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23146"}],"event":{"name":"ACSAC '18: 2018 Annual Computer Security Applications Conference","location":"San Juan PR USA","acronym":"ACSAC '18","sponsor":["ACSA Applied Computing Security Assoc"]},"container-title":["Proceedings of the 34th Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3274694.3274714","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3274694.3274714","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T00:57:56Z","timestamp":1750208276000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3274694.3274714"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,12,3]]},"references-count":49,"alternative-id":["10.1145\/3274694.3274714","10.1145\/3274694"],"URL":"https:\/\/doi.org\/10.1145\/3274694.3274714","relation":{},"subject":[],"published":{"date-parts":[[2018,12,3]]},"assertion":[{"value":"2018-12-03","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}