Click This, Not That: Extending Web Authentication with Deception

Click This, Not That: Extending Web Authentication with Deception
复制标题

点击这个,而不是那个:通过欺骗扩展 Web 身份验证

DOI:
10.1145/3433210.3453088
复制
发表时间:
2021
期刊:
Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security (ASIACCS
影响因子:
--
通讯作者:
Nikiforakis, Nick
Nikiforakis, Nick
中科院分区:
--
文献类型:
--
作者:
Barron, Timothy;So, Johnny;Nikiforakis, Nick

文献摘要

参考文献

被引文献

相似文献

随着网络钓鱼攻击、密码泄露和暴力登录攻击不断带来威胁,很明显,仅靠密码不足以保护托管我们个人数据的Web应用程序。相反,Web应用程序应该进行深度防御,并为用户提供多种方法来保护他们的account.In本文中,我们提出了登录仪式,定义用户必须采取的身份验证操作,以及Web绊网,定义用户必须采取的保持身份验证的操作。这些操作概述了熟悉其个人设置的用户在其经常使用的应用程序上的预期行为。我们展示了如何检测和防止网络攻击者的入侵,缺乏这种熟悉他们的受害者的行为。我们设计了一个模块化的和应用程序无关的系统,结合这两种机制,使我们能够添加一个额外的层欺骗为基础的安全现有的Web应用程序,而无需修改应用程序本身。下一个测试我们的系统,并评估其性能时,应用到五个流行的开源Web应用程序,我们通过用户研究证明了这些机制的前途。具体来说,我们评估了对模拟攻击者的绊网检测率,其中88%的人点击了至少一个绊网。我们还观察了网络用户创建的个性化登录仪式,并评估这些仪式的实用性和可记忆性。在39个用户创建的仪式中,所有的仪式都是独一无二的,79%的用户甚至在创建后一周就能够复制他们的仪式。
With phishing attacks, password breaches, and brute-force login attacks presenting constant threats, it is clear that passwords alone are inadequate for protecting the web applications entrusted with our personal data. Instead, web applications should practice defense in depth and give users multiple ways to secure their accounts.In this paper we propose login rituals, which define actions that a user must take to authenticate, and web tripwires, which define actions that a user must not take to remain authenticated. These actions outline expected behavior of users familiar with their individual setups on applications they use often. We show how we can detect and prevent intrusions from web attackers lacking this familiarity with their victim's behavior. We design a modular and application-agnostic system that incorporates these two mechanisms, allowing us to add an additional layer of deception-based security to existing web applications without modifying the applications themselves.Next to testing our system and evaluating its performance when applied to five popular open-source web applications, we demonstrate the promising nature of these mechanisms through a user study. Specifically, we evaluate the detection rate of tripwires against simulated attackers, 88% of whom clicked on at least one tripwire. We also observe web users' creation of personalized login rituals and evaluate the practicality and memorability of these rituals over time. Out of 39 user-created rituals, all of them are unique and 79% of users were able to reproduce their rituals even a week after creation.
游牧蜜罐:智能手机蜜罐的新颖概念
DOI: --
发表时间: 2013
期刊:
影响因子: --
作者:
Steffen Liebergeld;Matthias Lange;Collin Mulliner
通讯作者: Collin Mulliner
通过强身份验证改进端口碰撞
DOI: --
发表时间: 2005
期刊: Asia-Pacific Computer Systems Architecture Conference
影响因子: --
作者:
Rennie deGraaf;John Aycock;M. Jacobson
通讯作者: M. Jacobson
使用蜜罐对 IM 威胁进行系统表征
DOI: --
发表时间: 2010
期刊: Network and Distributed System Security Symposium
影响因子: --
作者:
Iasonas Polakis;Thanasis Petsas;E. Markatos;S. Antonatos
通讯作者: S. Antonatos
SCADA 蜜网:蜜罐作为检测和分析高级威胁的关键基础设施安全工具的吸引力
DOI: --
发表时间: 2011
期刊:
影响因子: --
作者:
S. Wade
通讯作者: S. Wade
使用混合端口敲门的网络安全
DOI: --
发表时间: 2010
期刊:
影响因子: --
作者:
H. Al;Ali Hadi
通讯作者: Ali Hadi