论文标题

这真的是你吗?关于在野外应用的基于风险身份验证的实证研究

Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the Wild

论文作者

Wiefling, Stephan, Iacono, Luigi Lo, Dürmuth, Markus

论文摘要

基于风险的身份验证(RBA)是一种适应性的安全措施,可增强基于密码的身份验证。 RBA在密码输入期间(例如设备或地理位置信息)监视其他隐式功能,如果检测到某个风险水平,请求其他身份验证因素。 NIST数字身份指南建议使用RBA,该指南由多个大型在线服务使用,并提供了防止安全风险的保护,例如密码数据库泄漏,凭据填充,不安全的密码和大规模的猜测攻击。尽管有相关性,但目前尚未披露由RBA上的在线服务使用的程序。因此,关于RBA的科学研究很少,放慢进步和更深入的理解,使最终用户更难理解他们使用和信任的服务提供的安全性,并阻碍了RBA的广泛采用。 在本文中,通过一系列关于八种流行在线服务的研究,我们(i)分析了哪些功能和组合/分类器被使用,并且在实际情况下很有用,(ii)开发了一种框架和方法来测量野外RBA,(iii)调查并讨论RBA用户界面的差异。此后,我们的工作提供了对实用RBA部署的首先了解,并有助于朝着这一方向发展进一步的研究。

Risk-based authentication (RBA) is an adaptive security measure to strengthen password-based authentication. RBA monitors additional implicit features during password entry such as device or geolocation information, and requests additional authentication factors if a certain risk level is detected. RBA is recommended by the NIST digital identity guidelines, is used by several large online services, and offers protection against security risks such as password database leaks, credential stuffing, insecure passwords and large-scale guessing attacks. Despite its relevance, the procedures used by RBA-instrumented online services are currently not disclosed. Consequently, there is little scientific research about RBA, slowing down progress and deeper understanding, making it harder for end users to understand the security provided by the services they use and trust, and hindering the widespread adoption of RBA. In this paper, with a series of studies on eight popular online services, we (i) analyze which features and combinations/classifiers are used and are useful in practical instances, (ii) develop a framework and a methodology to measure RBA in the wild, and (iii) survey and discuss the differences in the user interface for RBA. Following this, our work provides a first deeper understanding of practical RBA deployments and helps fostering further research in this direction.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源