首页> 外文会议>International symposium on cyberspace safety and security >Who Is Reusing Stolen Passwords? An Empirical Study on Stolen Passwords and Countermeasures
【24h】

Who Is Reusing Stolen Passwords? An Empirical Study on Stolen Passwords and Countermeasures

机译:谁在重用被盗的密码?密码被盗的实证研究及对策

获取原文

摘要

The combination of login passwords is still the most used identification and authentication method used on internet. Although if number of studies and articles pointed out the extreme weakness of using such authentication methods, almost every website is asking for a string password to create an account. Strong Password policies were created to reduce the risk of guessing or cracking a password string using traditional password crackers, but what is the benefit of such strong password construction if the whole credentials database is stolen and leaked? Every day hundreds of websites are breached and the content of their credential databases are exposed to the entire word. Millions of online accounts are then accessed illegally by various people with different level of damage impact. Who are these people? What is their purpose? How to prevent them from replaying stolen passwords? In this paper, we conduct an empirical study about the people who are reusing the stolen passwords found on internet or on the dark web. We deployed a fake Banking website in a honeypot mode, then we shared fake 3300 logins and passwords to the websites traditionally used for this purpose, finally we recorded their activities and made statistics. We also proposed a solution to reduce the attempts for replaying stolen passwords, and we measured the impact of this solution.
机译:登录密码的组合仍然是Internet上最常用的标识和身份验证方法。尽管许多研究和文章指出使用这种身份验证方法的极端缺点,但几乎每个网站都要求输入字符串密码来创建帐户。创建强密码策略是为了减少使用传统密码破解程序猜测或破解密码字符串的风险,但是,如果整个凭据数据库被盗和泄漏,那么采用这种强密码结构的好处是什么?每天都有数百个网站遭到破坏,其凭证数据库的内容暴露无遗。然后,数百万的在线帐户被具有不同程度的损害影响的各种人非法访问。这些人是谁?他们的目的是什么?如何防止他们重播被盗的密码?在本文中,我们对使用在互联网或黑网上发现的被盗密码的人进行了实证研究。我们以蜜罐模式部署了一个伪造的Banking网站,然后将伪造的3300登录名和密码共享到了传统上用于此目的的网站,最后我们记录了它们的活动并进行了统计。我们还提出了一种解决方案,以减少重播被盗密码的尝试,并评估了该解决方案的影响。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号