<p>Multifactor authentication (MFA) is an essential cybersecurity control. While the benefits are substantial, MFA also introduces friction that impacts the productivity of legitimate users. In this paper, we construct and analyze a dataset of authentication logs from a University population spanning two years. We focus on two costs experienced by users: (1) login failures and (2) the time spent away from IT applications following a failed authentication before attempting to re-authenticate. The second measure captures how user frustration can manifest by avoiding or delaying future engagement after experiencing failures. Following an exogenous change in MFA policy from a simple deny/approve notification to a more cumbersome approach, we observe significant increases in the number of login failures and in time spent away following failures. We also briefly examine which types of users had the greatest difficulty adjusting to the more secure mobile MFA procedure.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Quantifying Costs of Enhanced Security in Multifactor Authentication

  • Seth Hastings,
  • Tyler Moore,
  • Neil Gandal,
  • Noa Barnir

摘要

Multifactor authentication (MFA) is an essential cybersecurity control. While the benefits are substantial, MFA also introduces friction that impacts the productivity of legitimate users. In this paper, we construct and analyze a dataset of authentication logs from a University population spanning two years. We focus on two costs experienced by users: (1) login failures and (2) the time spent away from IT applications following a failed authentication before attempting to re-authenticate. The second measure captures how user frustration can manifest by avoiding or delaying future engagement after experiencing failures. Following an exogenous change in MFA policy from a simple deny/approve notification to a more cumbersome approach, we observe significant increases in the number of login failures and in time spent away following failures. We also briefly examine which types of users had the greatest difficulty adjusting to the more secure mobile MFA procedure.