Detecting stuffing of a user's credentials at her own accounts

Detecting stuffing of a user's credentials at her own accounts
复制标题

DOI:
--
复制
发表时间:
2019-12
期刊:
ArXiv
影响因子:
--
通讯作者:
K. Wang;M. Reiter
K. Wang;M. Reiter
中科院分区:
其他
文献类型:
--
作者:
K. Wang;M. Reiter

文献摘要

相似文献

我们提出了一个框架,网站可以通过该框架进行协调以检测个人用户帐户的撞库行为。我们的检测算法通过利用现代异常检测并仔细跟踪可疑登录,将正常登录行为(涉及密码重用、在错误站点输入正确密码等)与撞库行为区分开来。网站使用新颖的私人会员测试协议进行协调,从而确保有关密码的信息不会泄露;该协议具有高度可扩展性,部分原因是它使用了布谷鸟过滤器,并且在我们定义的一项重要措施中比类似可扩展的替代方案更安全。我们使用概率模型检查来估计一系列操作点的撞库检测准确性。这些方法可能因其新颖的形式化方法应用来估计我们设计的可用性影响而具有独立的意义。我们表明,即使是我们框架的最小基础设施部署也应该已经支持美国航空公司、酒店、零售和消费银行业所经历的组合登录负载。
We propose a framework by which websites can coordinate to detect credential stuffing on individual user accounts. Our detection algorithm teases apart normal login behavior (involving password reuse, entering correct passwords into the wrong sites, etc.) from credential stuffing, by leveraging modern anomaly detection and carefully tracking suspicious logins. Websites coordinate using a novel private membership-test protocol, thereby ensuring that information about passwords is not leaked; this protocol is highly scalable, partly due to its use of cuckoo filters, and is more secure than similarly scalable alternatives in an important measure that we define. We use probabilistic model checking to estimate our credential-stuffing detection accuracy across a range of operating points. These methods might be of independent interest for their novel application of formal methods to estimate the usability impacts of our design. We show that even a minimal-infrastructure deployment of our framework should already support the combined login load experienced by the airline, hotel, retail, and consumer banking industries in the U.S.