论文标题

评估基于风险的重新认证方法

Evaluation of Risk-based Re-Authentication Methods

论文作者

Wiefling, Stephan, Patil, Tanvi, Dürmuth, Markus, Iacono, Luigi Lo

论文摘要

基于风险的身份验证(RBA)是一种自适应安全措施,可通过防止凭证填充,密码猜测或网络钓鱼攻击来提高基于密码的身份验证的安全性。如果观察到的特征值偏离登录历史记录中的通常的特征值,则RBA在登录过程中监视额外的功能,并要求进行附加的身份验证步骤。在最先进的RBA重新认证部署中,用户在其体内收到了带有数值代码的电子邮件,该电子邮件必须在在线服务上输入。尽管此过程对RBA的时间曝光和可用性有重大影响,但到目前为止,这些方面尚未研究。 我们介绍了两个RBA重新认证变体,以基于链接和另一种基于代码的方法来补充事实上的标准。然后,我们介绍了一项组间研究(n = 592)的结果,以评估这三种方法。我们的观察结果表明,结果表明,有可能加快RBA重新认证过程,而不会降低其安全性能也不降低其安全感知。但是,通过“魔术链接”的基于链接的重新认证使用户比第一次感知基于代码的方法更加焦虑。我们的评估强调了RBA重新认证不是统一程序的事实。我们总结了我们的发现并提供建议。

Risk-based Authentication (RBA) is an adaptive security measure that improves the security of password-based authentication by protecting against credential stuffing, password guessing, or phishing attacks. RBA monitors extra features during login and requests for an additional authentication step if the observed feature values deviate from the usual ones in the login history. In state-of-the-art RBA re-authentication deployments, users receive an email with a numerical code in its body, which must be entered on the online service. Although this procedure has a major impact on RBA's time exposure and usability, these aspects were not studied so far. We introduce two RBA re-authentication variants supplementing the de facto standard with a link-based and another code-based approach. Then, we present the results of a between-group study (N=592) to evaluate these three approaches. Our observations show with significant results that there is potential to speed up the RBA re-authentication process without reducing neither its security properties nor its security perception. The link-based re-authentication via "magic links", however, makes users significantly more anxious than the code-based approaches when perceived for the first time. Our evaluations underline the fact that RBA re-authentication is not a uniform procedure. We summarize our findings and provide recommendations.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源