首页> 外文会议>2012 42nd Annual IEEE/IFIP International Conference on Dependable Systems and Networks >Safeguarding academic accounts and resources with the University Credential Abuse Auditing System
【24h】

Safeguarding academic accounts and resources with the University Credential Abuse Auditing System

机译:通过大学证书滥用审核系统保护学术帐户和资源

获取原文
获取原文并翻译 | 示例

摘要

Whether it happens through malware or through phishing, loss of one's online identity is a real and present danger. While many attackers seek credentials to realize financial gain, an analysis of the compromised accounts at our own institutions reveals that perpetrators often steal university credentials to gain free and unfettered access to information. This nontraditional motivation for credential theft puts a special burden on the academic institutions that provide these accounts. In this paper, we describe the design, implementation, and evaluation of a system for safeguarding academic accounts and resources called the University Credential Abuse Auditing System (UCAAS). We evaluate UCAAS at two major research universities with tens of thousands of user accounts and millions of login events during a two-week period. We show the UCAAS to be useful in reducing this burden, having helped the university security teams identify a total of 125 compromised accounts with zero false positives during the trail.
机译:无论是通过恶意软件还是通过网络钓鱼进行的,失去在线身份都是现实存在的危险。尽管许多攻击者都在寻求凭证以实现经济利益,但对我们自己机构中被盗帐户的分析表明,犯罪者经常窃取大学凭证来自由自由地获取信息。凭证盗窃的这种非传统动机给提供这些账户的学术机构带来了特殊的负担。在本文中,我们描述了一种保护学术帐户和资源的系统(称为大学证书滥用审核系统(UCAAS))的设计,实施和评估。我们在两周的时间内对两所拥有数万个用户帐户和数百万次登录事件的主要研究大学进行了UCAAS评估。我们证明了UCAAS在减轻这种负担方面的作用,它已帮助大学安全团队在跟踪过程中识别出了125个虚假肯定为零的受害帐户。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号