Using Amnesia to Detect Credential Database Breaches
Using Amnesia to Detect Credential Database Breaches
复制标题
DOI:
--
复制
发表时间:
2021
期刊:
影响因子:
--
通讯作者:
K. Wang;M. Reiter
中科院分区:
文献类型:
--
作者:
K. Wang;M. Reiter
Known approaches for using decoy passwords (honeywords) to detect credential database breaches su ff er from the need for a trusted component to recognize decoys when entered in login attempts, and from an attacker’s ability to test stolen passwords at other sites to identify user-chosen passwords based on their reuse at those sites. Amnesia is a framework that resolves these di ffi culties. Amnesia requires no secret state to detect the entry of honeywords and additionally allows a site to monitor for the entry of its decoy passwords elsewhere. We quantify the benefits of Amnesia using probabilistic model checking and the practicality of this framework through measurements of a working implementation.