【24h】

Dissuading Stolen Password Reuse

机译:劝阻被盗的密码重用

获取原文
获取原文并翻译 | 示例

摘要

The whole security community agreed on the fact that login and password based authentication systems are one of the weakest point of the current systems. Despite this global consensus password based credentials are still the most used identification and authentication method used on internet. One of the main reason for this weakness is due to the password leak phenomena. For several reasons (described in this paper) password databases are frequently leaked and shared publicly. Once these passwords it will be very hard for a user to protect his digital life, especially if this password is used in several websites (what we call domino effect). In this paper we propose a solution to reduce the attempts for replaying stolen passwords. We measure the efficiency of this solution via a deployment and the analysis on a fake website exposed to a fake password leak.
机译:整个安全社区都同意基于登录名和密码的身份验证系统是当前系统的最弱点之一的事实。尽管有这种全球共识,但基于密码的凭据仍然是Internet上最常用的标识和身份验证方法。造成此漏洞的主要原因之一是由于密码泄漏现象。由于多种原因(本文所述),密码数据库经常被泄漏并公开共享。一旦使用了这些密码,用户将很难保护自己的数字生活,尤其是如果在多个网站中使用了该密码(我们称之为多米诺效应)。在本文中,我们提出了一种解决方案,以减少重播被盗密码的尝试。我们通过对暴露于伪造密码泄露中的伪造网站进行部署和分析来衡量该解决方案的效率。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号