Security and Usability of Authentication by Challenge Questions in Online Examination
Abstract
Online examinations are an integral component of many online learning environments and a high-stake process for students, teachers and educational institutions. They are the target of many security threats, including intrusion by hackers and collusion. Collu-sion happens when a student invites a third party to impersonate him/her in an online test, or to abet with the exam questions. This research proposed a profile-based chal-lenge question approach to create and consolidate a student’s profile during the learning process, to be used for authentication in the examination process. The pro-posed method was investigated in six research studies using a usability test method and a risk-based security assessment method, in order to investigate usability attributes and security threats.
The findings of the studies revealed that text-based questions are prone to usability issues such as ambiguity, syntactic variation, and spelling mistakes. The results of a usability analysis suggested that image-based questions are more usable than text-based questions (p < 0.01). The findings identified that dynamic profile questions are more efficient and effective than text-based and image-based questions (p < 0.01). Since text-based questions are associated with an individual’s personal information, they are prone to being shared with impersonators. An increase in the numbers of chal-lenge questions being shared showed a significant linear trend (p < 0.01) and increased the success of an impersonation attack. An increase in the database size decreased the success of an impersonation attack with a significant linear trend (p < 0.01). The security analysis of dynamic profile questions revealed that an impersonation attack was not successful when a student shared credentials using email asynchronously. However, a similar attack was successful when a student and impersonator shared information in real time using mobile phones. The response time in this attack was significantly different when a genuine student responded to his challenge questions (p < 0.01). The security analysis revealed that the use of dynamic profile questions in a proctored exam can influence impersonation and abetting. This view was supported by online programme tutors in a focus group study.
Publication date
2017-05-12Published version
https://doi.org/10.18745/th.18186https://doi.org/10.18745/th.18186
Other links
http://hdl.handle.net/2299/18186Metadata
Show full item recordRelated items
Showing items related by title, author, creator and subject.
-
Questioning the Importance of Being Earnest: A Conversation Analysis of the Use and Function of Humour in the Serious Business of Therapy
Jeffrey, Sarah Kathering (2010-05-27)This thesis explores the long-standing debate in the field of psychotherapy around the use of humour in psychotherapy and the shift from outcome to process research in psychotherapy research. In line with the social ... -
London Charity Beneficiaries, c. 1800-1834: Questions of Agency
Webber, Megan (2016-11-21)In recent decades historians have ‘discovered’ agency in a wide range of geographical and temporal contexts, amongst many different types of actor. This dissertation employs the concept of agency to dissect the dynamics ... -
Narratives of Mental Health Professionals Supporting Trans, Gender Diverse and Gender Questioning Adults
Canvin, Lauren (2020-10-19)Trans, gender diverse and gender questioning people appear at a high risk of suffering from mental health difficulties, but often describe having negative experiences accessing both physical and mental healthcare in the ...