首页> 外文期刊>Computers & Security >Towards identifying and preventing behavioral side channel attack on recording attack resilient unaided authentication services
【24h】

Towards identifying and preventing behavioral side channel attack on recording attack resilient unaided authentication services

机译:旨在在记录攻击可恢复的独立身份验证服务上识别和防止行为侧信道攻击

获取原文
获取原文并翻译 | 示例

摘要

Side channel attacks, based on the human behavior, have not received much attention in the domain of recording attack resilient unaided authentication services (RARUAS) that purely rely on human visual perception but not on hidden auxiliary channels. In this paper, for the first time, we have made an extensive analysis to show - how human behavior during the login can weaken the claimed security standard of RARUAS. We identify this threat as behavioral side channel attack. To make situation more alarming, our investigation revealed that the identified threat model is capable of reducing the claimed session resiliency of any RARUAS by a significant extent. For dealing with this threat model, the latter part of our proposal introduces a novel defense strategy that reduces attackers' efficiency and improves the session resiliency. The subsequent study indicates that by nature of its design, the pro- posed defense strategy does not make any significant impact on the usability standard. To validate our claims, we have made a thorough experimental study to show that the pro- posed defense strategy is truly deployable in practice for improving the situation against the behavioral side channel attack. (C) 2019 Elsevier Ltd. All rights reserved.
机译:基于人类行为的侧信道攻击在记录攻击可恢复的独立认证服务(RARUAS)领域中并未引起太多关注,该服务仅依赖于人类的视觉感知,而不依赖于隐藏的辅助信道。在本文中,我们首次进行了广泛的分析,以显示-登录期间的人为行为如何削弱RARUAS声称的安全标准。我们将这种威胁确定为行为方面的渠道攻击。为了使情况更加令人震惊,我们的调查显示,所识别的威胁模型能够在很大程度上降低任何RARUAS声称的会话弹性。为了处理这种威胁模型,我们建议的后一部分引入了一种新颖的防御策略,该策略会降低攻击者的效率并提高会话的弹性。随后的研究表明,根据其设计的性质,建议的防御策略不会对可用性标准产生任何重大影响。为了验证我们的主张,我们进行了详尽的实验研究,以表明所提议的防御策略在实践中确实可以部署,以改善针对行为侧通道攻击的情况。 (C)2019 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号