首页> 外文期刊>Computers & Security >Towards identifying and preventing behavioral side channel attack on recording attack resilient unaided authentication services
【24h】

Towards identifying and preventing behavioral side channel attack on recording attack resilient unaided authentication services

机译:旨在识别和防止行为侧信道攻击对录制攻击弹性无可统治认证服务

获取原文
获取原文并翻译 | 示例

摘要

Side channel attacks, based on the human behavior, have not received much attention in the domain of recording attack resilient unaided authentication services (RARUAS) that purely rely on human visual perception but not on hidden auxiliary channels. In this paper, for the first time, we have made an extensive analysis to show - how human behavior during the login can weaken the claimed security standard of RARUAS. We identify this threat as behavioral side channel attack. To make situation more alarming, our investigation revealed that the identified threat model is capable of reducing the claimed session resiliency of any RARUAS by a significant extent. For dealing with this threat model, the latter part of our proposal introduces a novel defense strategy that reduces attackers' efficiency and improves the session resiliency. The subsequent study indicates that by nature of its design, the pro- posed defense strategy does not make any significant impact on the usability standard. To validate our claims, we have made a thorough experimental study to show that the pro- posed defense strategy is truly deployable in practice for improving the situation against the behavioral side channel attack. (C) 2019 Elsevier Ltd. All rights reserved.
机译:基于人类行为的侧信机攻击在纯粹依赖于人类视觉感知但不在隐藏的辅助通道上的录制攻击弹性的域中没有受到大量关注。在本文中,我们第一次进行了广泛的分析来展示 - 登录期间的人类行为如何削弱Raruas的索赔安全标准。我们将这种威胁识别为行为侧渠道攻击。为了使情况更加令人担忧,我们的调查透露,所确定的威胁模型能够在很大程度上减少任何RaruA的所要求保护的会议弹性。为了处理这种威胁模型,我们提案的后半部分介绍了一种新的防御策略,可降低攻击者的效率并提高会话弹性。随后的研究表明,由于其设计的性质,提供的防御策略对可用性标准没有任何重大影响。为了验证我们的索赔,我们已经进行了彻底的实验研究,以表明,在实践中,可以在实践中确实可以在实践中进行措施,以改善行为侧渠道攻击的情况。 (c)2019 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号