SoK: A Comprehensive Evaluation of 2FA-based Schemes in the Face of Active Concurrent Attacks from User Terminal

SoK: A Comprehensive Evaluation of 2FA-based Schemes in the Face of Active Concurrent Attacks from User Terminal
复制标题

DOI:
10.1145/3558482.3590183
复制
发表时间:
2023-05
期刊:
Proceedings of the 16th ACM Conference on Security and Privacy in Wireless and Mobile Networks
影响因子:
--
通讯作者:
Ahmed Tanvir Mahdad;Nitesh Saxena
Ahmed Tanvir Mahdad;Nitesh Saxena
中科院分区:
其他
文献类型:
--
作者:
Ahmed Tanvir Mahdad;Nitesh Saxena

文献摘要

相似文献

受恶意软件感染的终端对身份验证系统构成普遍威胁。由于仅使用密码的身份验证无法充分防止终端上的恶意软件,因此文献提出了几种声称在存在重大安全威胁(包括受感染的终端)的情况下提供安全性的身份验证方法。大多数方法都在身份验证过程中加入了一个独立于密码的因素,以减轻这些威胁。根据文献中的社区观点,面向2FA的方法在认证终端上存在恶意软件的情况下似乎是安全的。在这项工作中,我们系统化这些基于2FA的学术方案的威胁模型和认证过程,以研究它们如何确保认证过程中每一步的安全性。此外,我们提出了一个积极的并发攻击框架CSI(并发会话注入),并做了一个全面的分析研究学术认证系统对它。此外,我们系统化的安全认证系统,从文献中声称提供保护,以防止用户终端恶意软件和并发攻击,并指出其潜在的漏洞。我们的研究强调了针对此类威胁采取适当安全措施的重要性,并为在未来的研究中设计更安全的认证系统创造了机会。
Malware-infected terminals pose a pervasive threat to authentication systems. As password-only authentication cannot adequately protect against malware on terminals, the literature proposes several authentication methods claiming to provide security in the presence of significant security threats, including infected terminals. Most methods incorporate a password-independent factor in the authentication process to mitigate these threats. According to the community view in the literature, 2FA-oriented methods appear to be secure in the presence of malware on the authentication terminal. In this work, we systematize these 2FA-based academic schemes' threat models and authentication procedures to examine how they ensure security at every step of the authentication process. Additionally, we present an active concurrent attack framework named CSI(Concurrent Session Injection) and have done a comprehensive analysis of studied academic authentication systems against it. Furthermore, we systematize secure authentication systems from the literature that claim to provide protection against user terminal malware and concurrent attacks and point out their potential vulnerabilities. Our research emphasizes the significance of taking proper security measures against such threats and creates the opportunity to design more secure authentication systems in future research.