Computer Security - ESORICS 2023 - 28th European Symposium on Research in Computer Security, The Hague, The Netherlands, September 25-29, 2023, Proceedings, Part III

Computer Security - ESORICS 2023 - 28th European Symposium on Research in Computer Security, The Hague, The Netherlands, September 25-29, 2023, Proceedings, Part III
复制标题

计算机安全 - ESORICS 2023 - 第 28 届欧洲计算机安全研究研讨会,荷兰海牙,2023 年 9 月 25-29 日,会议记录,第三部分

DOI:
10.1007/978-3-031-51479-1_23
复制
发表时间:
2024
期刊:
--
影响因子:
--
通讯作者:
Arnaboldi L
Arnaboldi L
中科院分区:
--
文献类型:
--
作者:
Arnaboldi L

文献摘要

相似文献

帐户访问图已经被提出作为一种对用户凭证、帐户和访问方法之间的关系进行建模的方式;它们捕获多个同时访问路由(例如,用于多因素认证)以及多个备选接入路由(例如,账户恢复)。在本文中,我们扩展了形式主义的状态转换和策略。状态转换捕获访问如何随着用户或对手使用访问路由以及添加或删除凭据和帐户而随时间变化。策略使我们能够通过编写小程序来建模和记录攻击者技术或弹性策略。我们使用2023年公布的针对移动的身份验证和银行应用程序的一些攻击来说明这些想法。
Account access graphs have been proposed as a way to model relationships between user credentials, accounts, and methods of access; they capture both multiple simultaneous access routes (e.g., for multi-factor authentication) as well as multiple alternative access routes (e.g., for account recovery). In this paper we extend the formalism with state transitions and tactics. State transitions capture how access may change over time as users or adversaries use access routes and add or remove credentials and accounts. Tactics allow us to model and document attacker techniques or resilience strategies, by writing small programs. We illustrate these ideas using some attacks against mobile authentication and banking applications which have been publicised in 2023.