서브메뉴
검색
Characterizing and Detecting Password Guessing Attacks.
Characterizing and Detecting Password Guessing Attacks.
- 자료유형
- 학위논문
- Control Number
- 0017161410
- International Standard Book Number
- 9798382842486
- Dewey Decimal Classification Number
- 004
- Main Entry-Personal Name
- Bohuk, Marina Sanusi.
- Publication, Distribution, etc. (Imprint
- [S.l.] : Cornell University., 2024
- Publication, Distribution, etc. (Imprint
- Ann Arbor : ProQuest Dissertations & Theses, 2024
- Physical Description
- 187 p.
- General Note
- Source: Dissertations Abstracts International, Volume: 85-12, Section: B.
- General Note
- Advisor: Ristenpart, Thomas.
- Dissertation Note
- Thesis (Ph.D.)--Cornell University, 2024.
- Summary, Etc.
- 요약Modern authentication systems still mainly rely on passwords for authentication, but little is known about legitimate and malicious user behavior during the authentication process due to the difficulty of collecting information on such a sensitive field. Because passwords are hard to remember and often reused across websites, they are prone to remote guessing attacks in which an attacker iterates through a guess list of credentials, submitting them against a live login system; but existing defenses do not leverage password-based information because of the challenge of collecting such information in a secure way.We address this challenge first by developing a measurement framework called Gossamer for securely recording password-derived measurements, which we used to collect data on 34 million login requests at two universities. Then, we show how we used the data collected by Gossamer to develop a clustering approach called Arana that detects and groups login requests into attack campaigns. Finally, we explore existing timely attack detection mechanisms and evaluate them on Gossamer data along with three new detection methods based on Directed Anomaly Scoring. We also show that these detection methods are vulnerable to evasion attacks by an adaptive attacker.
- Subject Added Entry-Topical Term
- Computer science.
- Subject Added Entry-Topical Term
- Computer engineering.
- Subject Added Entry-Topical Term
- Information technology.
- Index Term-Uncontrolled
- Authentication
- Index Term-Uncontrolled
- Passwords
- Index Term-Uncontrolled
- Privacy
- Index Term-Uncontrolled
- Security
- Index Term-Uncontrolled
- Arana
- Added Entry-Corporate Name
- Cornell University Computer Science
- Host Item Entry
- Dissertations Abstracts International. 85-12B.
- Electronic Location and Access
- 로그인을 한후 보실 수 있는 자료입니다.
- Control Number
- joongbu:658306