首页> 外文期刊>IOSR journal of computer engineering >An Enhanced Password-Username Authentication System Using Cryptographic Hashing and Recognition Based Graphical Password
【24h】

An Enhanced Password-Username Authentication System Using Cryptographic Hashing and Recognition Based Graphical Password

机译:使用基于密码散列和识别的图形密码的增强型密码用户名认证系统

获取原文
获取原文并翻译 | 示例
           

摘要

Password-username authentication is a critical component of today's web application technology that is commonly used to control access to restricted resources. However, poor design, coding flaws and weak user login credentials exposes this functionality to Sequel Query Language Injection (SQLI) and online password guessing attacks. Current techniques advanced by researchers to address authentication attacks only focus on either one of them, thus failing to envisage a scenario where the login form can be used to launch both SQLI and online password guessing attacks. To address this challenge, this paper presents an authentication solution that addresses the issue of SQLI and online password guessing attacks on login form as implemented in generic web applications. The solution combines the use of plain text credentials that are cryptographically hashed at runtime with recognition based graphical login credentials. The goal is to always guarantee access to a user account even when such account is under attack while at the same time ensuring convenient and secure login experience by legitimate users. This is achieved by blocking the Internet Protocol (IP) address from which there are unsuccessful login attempts. Security test shows that the solution is not vulnerable to SQLI and online password guessing attacks.
机译:密码用户名认证是当今Web应用程序技术的重要组成部分,通常用于控制对受限资源的访问。但是,不良的设计,编码缺陷和较弱的用户登录凭据使此功能容易受到Sequel查询语言注入(SQLI)和在线密码猜测攻击的攻击。研究人员当前用于解决身份验证攻击的先进技术仅集中于其中之一,因此无法设想一种情况,即可以使用登录表单来发起SQLI和在线密码猜测攻击。为了解决这一挑战,本文提出了一种身份验证解决方案,该解决方案解决了在通用Web应用程序中实现的针对登录表单的SQLI和在线密码猜测攻击的问题。该解决方案将在运行时通过密码哈希加密的纯文本凭据与基于识别的图形登录凭据结合使用。目标是始终保证即使在用户帐户受到攻击时也可以访问该用户帐户,同时确保合法用户的便利和安全的登录体验。这是通过阻止尝试登录失败的Internet协议(IP)地址来实现的。安全测试表明,该解决方案不易受到SQLI和在线密码猜测攻击的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号