Using Amnesia to Detect Credential Database Breaches

Using Amnesia to Detect Credential Database Breaches
复制标题

DOI:
--
复制
发表时间:
2021
期刊:
--
影响因子:
--
通讯作者:
K. Wang;M. Reiter
K. Wang;M. Reiter
中科院分区:
其他
文献类型:
--
作者:
K. Wang;M. Reiter

文献摘要

被引文献

相似文献

使用诱饵密码(honeywords)来检测凭证数据库泄露的已知方法需要受信任的组件在登录尝试中输入时识别诱饵,并且攻击者能够在其他站点测试被盗密码,以根据用户在这些站点的重用情况来识别用户选择的密码。 Amnesia 是一个解决这些困难的框架。 Amnesia 不需要秘密状态来检测 honeywords 的输入,并且还允许站点在其他地方监视其诱饵密码的输入。我们使用概率模型检查来量化 Amnesia 的好处,并通过测量工作实现来量化该框架的实用性。
Known approaches for using decoy passwords (honeywords) to detect credential database breaches su ff er from the need for a trusted component to recognize decoys when entered in login attempts, and from an attacker’s ability to test stolen passwords at other sites to identify user-chosen passwords based on their reuse at those sites. Amnesia is a framework that resolves these di ffi culties. Amnesia requires no secret state to detect the entry of honeywords and additionally allows a site to monitor for the entry of its decoy passwords elsewhere. We quantify the benefits of Amnesia using probabilistic model checking and the practicality of this framework through measurements of a working implementation.