Year

2024

Season

Fall

Paper Type

Master's Thesis

College

College of Computing, Engineering & Construction

Degree Name

Master of Science in Computer and Information Sciences (MS)

Department

Computing

NACO controlled Corporate Body

University of North Florida. School of Computing

First Advisor

Dr. Swapnoneel Roy

Second Advisor

Dr. Sandeep Reddivari

Third Advisor

Dr. Iman Vakilinia

Department Chair

Dr. Zornitza Prodanoff

College Dean

Dr. William Klostermeyer

Abstract

Most organizations have established strong password policies and standards to ensure the confidentiality, integrity, and availability of their data, applications, and critical systems. Even with rigorous implementations and layered approaches such as utilizing multifactor authentications, there are still flaws and vulnerabilities as they have a high dependency on the user adhering to them. In conjunction with these policies, a strong security awareness program should be implemented to educate the end user about strong password hygiene. In this work, we design and implement a secure one-time password (OTP) system, “PassPerfect”, to provide a method of enforcing a strong set of password policies that bypass natural human habits of choosing passwords that do not adhere to the policies of an organization on their own. When users do this, they leave systems vulnerable to security threats. As part of a secure software development life cycle to ensure that there are no coding defects, errors, or vulnerabilities, a secure code review on PassPerfect is completed through static, functional, and/or dynamic code analysis.

Share

COinS