Daniela Pöhn , Nils Gruschka , Leonhard Ziegler , Andre Büttner
{"title":"A framework for analyzing authentication risks in account networks","authors":"Daniela Pöhn , Nils Gruschka , Leonhard Ziegler , Andre Büttner","doi":"10.1016/j.cose.2023.103515","DOIUrl":null,"url":null,"abstract":"<div><p><span>Our everyday life depends more and more on online services and, therefore, access to related user accounts. The security of user accounts, again, is tied to the security of the corresponding primary and fallback authentication methods. Accounts can be linked to each other – by fallback authentication, through SSO, or by using the same </span>authentication devices<span> – creating an account network. These account networks enhance login comfort and are needed in case of account recovery, but they also increase each account's attack surface. In addition, misconfigurations might result in account inaccessibility. However, these problems can only be detected by analyzing single accounts first and then the resulting account networks. Despite the importance to understand account security and accessibility, almost no analysis methods exist.</span></p><p><span>To address this need, this article presents the Authentication Analysis Framework (AAF). AAF evaluates account types and primary and fallback authentication methods for each account, before analyzing the overall account network. By detecting transitive risks, weak links can be discovered and subsequently strengthened. We further propose maturity models to rank the primary and fallback authentication methods based on risks and a description language to exchange the required information. AAF is implemented as a plugin for the </span>password manager KeePass to assist end users and as a standalone tool for researchers.</p></div>","PeriodicalId":51004,"journal":{"name":"Computers & Security","volume":"135 ","pages":"Article 103515"},"PeriodicalIF":4.8000,"publicationDate":"2023-10-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Computers & Security","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S016740482300425X","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0
Abstract
Our everyday life depends more and more on online services and, therefore, access to related user accounts. The security of user accounts, again, is tied to the security of the corresponding primary and fallback authentication methods. Accounts can be linked to each other – by fallback authentication, through SSO, or by using the same authentication devices – creating an account network. These account networks enhance login comfort and are needed in case of account recovery, but they also increase each account's attack surface. In addition, misconfigurations might result in account inaccessibility. However, these problems can only be detected by analyzing single accounts first and then the resulting account networks. Despite the importance to understand account security and accessibility, almost no analysis methods exist.
To address this need, this article presents the Authentication Analysis Framework (AAF). AAF evaluates account types and primary and fallback authentication methods for each account, before analyzing the overall account network. By detecting transitive risks, weak links can be discovered and subsequently strengthened. We further propose maturity models to rank the primary and fallback authentication methods based on risks and a description language to exchange the required information. AAF is implemented as a plugin for the password manager KeePass to assist end users and as a standalone tool for researchers.
期刊介绍:
Computers & Security is the most respected technical journal in the IT security field. With its high-profile editorial board and informative regular features and columns, the journal is essential reading for IT security professionals around the world.
Computers & Security provides you with a unique blend of leading edge research and sound practical management advice. It is aimed at the professional involved with computer security, audit, control and data integrity in all sectors - industry, commerce and academia. Recognized worldwide as THE primary source of reference for applied research and technical expertise it is your first step to fully secure systems.