首页> 外文期刊>Journal of network and computer applications >Attacks and defenses in user authentication systems: A survey
【24h】

Attacks and defenses in user authentication systems: A survey

机译:用户身份验证系统中的攻击和防御:调查

获取原文
获取原文并翻译 | 示例

摘要

User authentication systems (in short authentication systems) have wide utilization in our daily life. Unfortunately, existing authentication systems are prone to various attacks while both system security and usability are expected to be satisfied. But the current research still lacks a thorough survey on various types of attacks and corresponding countermeasures regarding user authentication, including traditional password-based and emerging biometric-based systems. In this paper, we make a comprehensive review on attacks and defenses of the authentication systems. We firstly introduce a number of common attacks by classifying them into different categories based on attacker knowledge, attack target, attack form and attack strength. Then, we propose a set of evaluation criteria for evaluating different kinds of attack defense mechanisms. Furthermore, we review and evaluate the existing methods of detecting and resisting attacks in the authentication systems by employing the proposed evaluation criteria as a common measure. Specifically, we focus on comparing and analyzing the performance of different defense mechanisms in different types of authentication systems. Through serious review and analysis, we put forward a number of open issues and propose some promising future research directions, hoping to inspire further research in this field.
机译:用户身份验证系统(在简短的身份验证系统中)在日常生活中具有广泛的利用率。不幸的是,现有的身份验证系统容易出现各种攻击,而预计系统安全性和可用性则会满足。但目前的研究仍然对各种类型的攻击和对用户认证的相应对策,包括传统密码和新兴的基于生物识别的系统的彻底调查。在本文中,我们对认证系统的攻击和防御进行了全面的审查。我们首先通过将它们分类为基于攻击者知识,攻击目标,攻击形式和攻击力量来分类到不同类别的许多常见攻击。然后,我们提出了一系列评估标准,用于评估不同种类的攻击防范机制。此外,我们通过采用所提出的评估标准作为一种常见措施,审查和评估通过拟议的评估标准来检测和抵抗认证系统中的攻击的现有方法。具体而言,我们专注于比较和分析不同类型的认证系统中不同防御机制的性能。通过认真的审查和分析,我们提出了一些开放问题并提出了一些未来的未来研究方向,希望激励在这一领域进一步研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号