Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password Authentication

Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password Authentication
复制标题

DOI:
10.1145/3460120.3484791
复制
发表时间:
2021-11
期刊:
Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Sena Sahin;Frank H. Li
Sena Sahin;Frank H. Li
中科院分区:
其他
文献类型:
--
作者:
Sena Sahin;Frank H. Li

文献摘要

相似文献

为了增强密码身份验证的可用性,易于使用的密码身份验证方案允许用户提供的密码中某些偏差,以说明常见的印刷错误,但仍允许用户成功登录。在先前的工作中,Chatterjee等人的分析。证明Typo-colerance确实显着提高了密码可用性,但(令人惊讶的是)似乎并未显着降低身份验证安全性。实际上,诸如Facebook之类的主要Web服务已采用了易于使用的密码身份验证系统。在本文中,我们重新审视了易于耐受性的密码身份验证的安全性影响。我们观察到,对此类系统的现有安全分析仅考虑密码喷涂攻击。但是,此威胁模型是不完整的,因为密码身份验证系统还必须与凭证填充和调整攻击有关。在这些缺失的攻击向量中,我们通过经验重新评估了使用密码泄漏数据集对密码耐受性的安全性影响,发现安全性的降级明显更大。为了减轻此问题,我们探索了机器学习分类器,这些分类器可以预测何时可能会受到错字的影响。我们最终的模型在功能安全折衷范围上提供了各种合适的操作点,最终允许部分部署通用的密码身份验证,并为许多用户保留其功能,同时降低安全风险。
To enhance the usability of password authentication, typo-tolerant password authentication schemes permit certain deviations in the user-supplied password, to account for common typographical errors yet still allow the user to successfully log in. In prior work, analysis by Chatterjee et al. demonstrated that typo-tolerance indeed notably improves password usability, yet (surprisingly) does not appear to significantly degrade authentication security. In practice, major web services such as Facebook have employed typo-tolerant password authentication systems. In this paper, we revisit the security impact of typo-tolerant password authentication. We observe that the existing security analysis of such systems considers only password spraying attacks. However, this threat model is incomplete, as password authentication systems must also contend with credential stuffing and tweaking attacks. Factoring in these missing attack vectors, we empirically re-evaluate the security impact of password typo-tolerance using password leak datasets, discovering a significantly larger degradation in security. To mitigate this issue, we explore machine learning classifiers that predict when a password's security is likely affected by typo-tolerance. Our resulting models offer various suitable operating points on the functionality-security tradeoff spectrum, ultimately allowing for partial deployment of typo-tolerant password authentication, preserving its functionality for many users while reducing the security risks.