{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T18:56:17Z","timestamp":1772909777514,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,8,29]],"date-time":"2023-08-29T00:00:00Z","timestamp":1693267200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,8,29]]},"DOI":"10.1145\/3600160.3605024","type":"proceedings-article","created":{"date-parts":[[2023,8,9]],"date-time":"2023-08-09T22:54:41Z","timestamp":1691621681000},"page":"1-9","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Evaluation of Real-World Risk-Based Authentication at Online Services Revisited: Complexity Wins"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-8699-2867","authenticated-orcid":false,"given":"Jan-Phillip","family":"Makowski","sequence":"first","affiliation":[{"name":"Universit\u00e4t der Bundeswehr M\u00fcnchen, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6373-3637","authenticated-orcid":false,"given":"Daniela","family":"P\u00f6hn","sequence":"additional","affiliation":[{"name":"Universit\u00e4t der Bundeswehr M\u00fcnchen, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,8,29]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Proceedings of the 7th USENIX Workshop on Hot Topics in Security (HotSec 12)","unstructured":"2012. The Benefits of Understanding Passwords. In Proceedings of the 7th USENIX Workshop on Hot Topics in Security (HotSec 12) (Bellevue, WA). https:\/\/www.usenix.org\/conference\/hotsec12\/workshop-program\/presentation\/Jakobsson"},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the 13th USENIX Symposium on Usable Privacy and Security (SOUPS)","year":"2017","unstructured":"2017. You Want Me To Do What? A Design Study of Two-Factor Authentication Messages. In Proceedings of the 13th USENIX Symposium on Usable Privacy and Security (SOUPS). Santa Clara, CA. https:\/\/www.usenix.org\/conference\/soups2017\/workshop-program\/way2017\/redmiles"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3313831.3376457"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3336117"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/3582696"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/CIC48465.2019.00043"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFCOM.2010.5461951"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW.2019.00020"},{"key":"e_1_3_2_1_10_1","unstructured":"EFF. 2023. Cover Your Tracks. https:\/\/coveryourtracks.eff.org\/. Accessed 2023\/07\/01 12:11:48."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/SIST54437.2022.9945766"},{"key":"e_1_3_2_1_12_1","unstructured":"ForgeRock. 2019. OpenAM 13 \u2013 Administration Guide. https:\/\/backstage.forgerock.com\/docs\/openam\/13.5\/admin-guide\/#adaptive-auth-module-conf-hints. Accessed 2023\/07\/01 12:11:48."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"David\u00a0Mandell Freeman Sakshi Jain Markus D\u00fcrmuth Battista Biggio and Giorgio Giacinto. 2016. Who Are you? A Statistical Approach to Measuring User Authenticity.","DOI":"10.14722\/ndss.2016.23240"},{"key":"e_1_3_2_1_14_1","volume-title":"Engin Kirda, Long Lu, Andre King, Andy Davis, and Tim Leek.","author":"Gavazzi Anthony","year":"2023","unstructured":"Anthony Gavazzi, Ryan williams, Engin Kirda, Long Lu, Andre King, Andy Davis, and Tim Leek. 2023. A Study of Multi-Factor and Risk-Based Authentication Availability. (2023). Prepublication of USENIX Security."},{"key":"e_1_3_2_1_15_1","unstructured":"Google. 2023. Chrome DevTools. https:\/\/developer.chrome.com\/docs\/devtools\/. Accessed 2023\/07\/01 12:11:48."},{"key":"e_1_3_2_1_16_1","unstructured":"Google. 2023. User-Agent-Switcher for Chrome. https:\/\/chrome.google.com\/webstore\/detail\/user-agent-switcher-for-c\/djflhoibgkdhkhhcedjiklpkjnoahfmg. Accessed 2023\/07\/01 12:11:48."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-63b"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2018.3191268"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3546118.3546152"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453084"},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of the 18th USENIX Symposium on Usable Privacy and Security (SOUPS)","author":"Markert Philipp","year":"2022","unstructured":"Philipp Markert, Theodor Schnitzler, Maximilian Golla, and Markus D\u00fcrmuth. 2022. \"As soon as it\u2019s a risk, I want to require MFA\": How Administrators Configure Risk-based Authentication. In Proceedings of the 18th USENIX Symposium on Usable Privacy and Security (SOUPS) (Boston, MA). 483\u2013501. https:\/\/www.usenix.org\/conference\/soups2022\/presentation\/markert"},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security)","author":"Mayer Peter","year":"2022","unstructured":"Peter Mayer, Collins\u00a0W. Munyendo, Michelle\u00a0L. Mazurek, and Adam\u00a0J. Aviv. 2022. Why Users (Don\u2019t) Use Password Managers at a Large Educational Institution. In Proceedings of the 31st USENIX Security Symposium (USENIX Security) (Boston, MA). 1849\u20131866. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/mayer"},{"key":"e_1_3_2_1_23_1","volume-title":"Affected Them. In Proceedings of the 30th USENIX Security Symposium (USENIX Security). 393\u2013410","author":"Mayer Peter","year":"2021","unstructured":"Peter Mayer, Yixin Zou, Florian Schaub, and Adam\u00a0J. Aviv. 2021. \"Now I\u2019m a bit angry:\" Individuals\u2019 Awareness, Perception, and Responses to Data Breaches that Affected Them. In Proceedings of the 30th USENIX Security Symposium (USENIX Security). 393\u2013410. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/mayer"},{"key":"e_1_3_2_1_24_1","volume-title":"Proceedings of USENIX Enigma (Enigma)","author":"Milka Grzergor","year":"2018","unstructured":"Grzergor Milka. 2018. Anatomy of Account Takeover. In Proceedings of USENIX Enigma (Enigma). Santa Clara, CA. https:\/\/www.usenix.org\/node\/208154"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","unstructured":"Mohammed Misbahuddin B\u00a0S Bindhumadhava and B. Dheeptha. 2017. Design of a risk based authentication system using machine learning techniques. In Proceedings of the IEEE SmartWorld Ubiquitous Intelligence & Computing Advanced & Trusted Computed Scalable Computing & Communications Cloud & Big Data Computing Internet of People and Smart City Innovation (SmartWorld\/SCALCOM\/UIC\/ATC\/CBDCom\/IOP\/SCI). 1\u20136. https:\/\/doi.org\/10.1109\/UIC-ATC.2017.8397628","DOI":"10.1109\/UIC-ATC.2017.8397628"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CAMAD55695.2022.9966915"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CAMAD55695.2022.9966901"},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the 15th USENIX Symposium on Usable Privacy and Security (SOUPS)","author":"Pearman Sarah","year":"2019","unstructured":"Sarah Pearman, Shikun\u00a0Aerin Zhang, Lujo Bauer, Nicolas Christin, and Lorrie\u00a0Faith Cranor. 2019. Why people (don\u2019t) use password managers effectively. In Proceedings of the 15th USENIX Symposium on Usable Privacy and Security (SOUPS) (Santa Clara, CA). 319\u2013338. https:\/\/www.usenix.org\/conference\/soups2019\/presentation\/pearman"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3538969.3544430"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2695664.2695908"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.3390\/app13042349"},{"key":"e_1_3_2_1_32_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security). 73\u201390","author":"Ray Hirak","year":"2021","unstructured":"Hirak Ray, Flynn Wolf, Ravi Kuber, and Adam\u00a0J. Aviv. 2021. Why Older Adults (Don\u2019t) Use Password Managers. In Proceedings of the 30th USENIX Security Symposium (USENIX Security). 73\u201390. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/ray"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3411508.3421377"},{"key":"e_1_3_2_1_34_1","volume-title":"Applied Cryptography and Network Security Workshops","author":"Rivera Esteban","unstructured":"Esteban Rivera, Lizzy Tengana, Jes\u00fas Solano, Christian L\u00f3pez, Johana Fl\u00f3rez, and Mart\u00edn Ochoa. 2022. Scalable and Secure HTML5 Canvas-Based User Authentication. In Applied Cryptography and Network Security Workshops, Jianying Zhou, Sridhar Adepu, Cristina Alcaraz, Lejla Batina, Emiliano Casalicchio, Sudipta Chattopadhyay, Chenglu Jin, Jingqiang Lin, Eleonora Losiouk, Suryadipta Majumdar, Weizhi Meng, Stjepan Picek, Jun Shao, Chunhua Su, Cong Wang, Yury Zhauniarovich, and Saman Zonouz (Eds.). Springer International Publishing, 554\u2013574."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2751323.2751329"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134067"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.5220\/0011656400003405"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427243"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-64331-0_19"},{"key":"e_1_3_2_1_40_1","volume-title":"Even Turing Should Sometimes Not Be Able to Tell: Mimicking Humanoid Usage Behavior for Exploratory Studies of Online Services","author":"Wiefling Stephan","unstructured":"Stephan Wiefling, Nils Gruschka, and Luigi Lo\u00a0Iacono. 2019. Even Turing Should Sometimes Not Be Able to Tell: Mimicking Humanoid Usage Behavior for Exploratory Studies of Online Services. In Secure IT Systems, Aslan Askarov, Ren\u00e9\u00a0Rydhof Hansen, and Willard Rafnsson (Eds.). Springer International Publishing, 188\u2013203."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/3546069"},{"key":"e_1_3_2_1_42_1","volume-title":"Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the Wild","author":"Wiefling Stephan","unstructured":"Stephan Wiefling, Luigi Lo\u00a0Iacono, and Markus D\u00fcrmuth. 2019. Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the Wild. In ICT Systems Security and Privacy Protection, Gurpreet Dhillon, Fredrik Karlsson, Karin Hedstr\u00f6m, and Andr\u00e9 Z\u00faquete (Eds.). Springer International Publishing, 134\u2013148."},{"key":"e_1_3_2_1_43_1","volume-title":"Evaluation of Risk-Based Re-Authentication Methods","author":"Wiefling Stephan","unstructured":"Stephan Wiefling, Tanvi Patil, Markus D\u00fcrmuth, and Luigi Lo\u00a0Iacono. 2020. Evaluation of Risk-Based Re-Authentication Methods. In ICT Systems Security and Privacy Protection, Marko H\u00f6lbl, Kai Rannenberg, and Tatjana Welzer (Eds.). Springer International Publishing, 280\u2013294."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW54576.2021.00040"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-92317-4_4"}],"event":{"name":"ARES 2023: The 18th International Conference on Availability, Reliability and Security","location":"Benevento Italy","acronym":"ARES 2023"},"container-title":["Proceedings of the 18th International Conference on Availability, Reliability and Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3605024","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3600160.3605024","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:16Z","timestamp":1750182556000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3600160.3605024"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,8,29]]},"references-count":45,"alternative-id":["10.1145\/3600160.3605024","10.1145\/3600160"],"URL":"https:\/\/doi.org\/10.1145\/3600160.3605024","relation":{},"subject":[],"published":{"date-parts":[[2023,8,29]]},"assertion":[{"value":"2023-08-29","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}