Information and Communications Security - 10th International Conference, ICICS 2008 Birmingham, UK, October 20 - 22, 2008 Proceedings

Information and Communications Security - 10th International Conference, ICICS 2008 Birmingham, UK, October 20 - 22, 2008 Proceedings
复制标题

信息和通信安全 - 第 10 届国际会议,ICICS 2008 英国伯明翰,2008 年 10 月 20 日至 22 日会议记录

DOI:
10.1007/978-3-540-88625-9_4
复制
发表时间:
2008
期刊:
--
影响因子:
--
通讯作者:
Dong X
Dong X
中科院分区:
--
文献类型:
--
作者:
Dong X

文献摘要

相似文献

用户身份验证可以通过破坏系统和破坏用户来破坏;前者的威胁建模得到了很好的研究,而后者的研究较少。我们提出了一种方法来确定颠覆用户的机会,从而系统地识别漏洞。该方法应用于VeriSign的OpenID认证机制。
User authentication can be compromised both by subverting the system and by subverting the user; the threat modelling of the former is well studied, the latter less so. We propose a method to determine opportunities to subvert the user allowing vulnerabilities to be systematically identified. The method is applied to VeriSign’s OpenID authentication mechanism.