Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password Authentication

被引:6
作者
Sahin, Sena [1 ]
Li, Frank [1 ]
机构
[1] Georgia Inst Technol, Atlanta, GA 30332 USA
来源
CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2021年
基金
美国国家科学基金会;
关键词
Password Authentication; Security Analysis; Machine Learning;
D O I
10.1145/3460120.3484791
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
To enhance the usability of password authentication, typo-tolerant password authentication schemes permit certain deviations in the user-supplied password, to account for common typographical errors yet still allow the user to successfully log in. In prior work, analysis by Chatterjee et al. demonstrated that typo-tolerance indeed notably improves password usability, yet (surprisingly) does not appear to significantly degrade authentication security. In practice, major web services such as Facebook have employed typo-tolerant password authentication systems. In this paper, we revisit the security impact of typo-tolerant password authentication. We observe that the existing security analysis of such systems considers only password spraying attacks. However, this threat model is incomplete, as password authentication systems must also contend with credential stuffing and tweaking attacks. Factoring in these missing attack vectors, we empirically re-evaluate the security impact of password typo-tolerance using password leak datasets, discovering a significantly larger degradation in security. To mitigate this issue, we explore machine learning classifiers that predict when a password's security is likely affected by typo-tolerance. Our resulting models offer various suitable operating points on the functionality-security tradeoff spectrum, ultimately allowing for partial deployment of typo-tolerant password authentication, preserving its functionality for many users while reducing the security risks.
引用
收藏
页码:252 / 270
页数:19
相关论文
共 38 条
[1]  
4iQ, 2020, WEAPONIZED DATA BREA
[2]  
Antilla Susan, 2015, IS VANGUARD MAKING I
[3]  
Bijeeta Pal, 2019, PASSWORD SIMILARITY
[4]  
Blanchard Enka., 2020, IEEE ANN COMP SOFTW
[5]   The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes [J].
Bonneau, Joseph ;
Herley, Cormac ;
van Oorschot, Paul C. ;
Stajano, Frank .
2012 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2012, :553-567
[6]  
Casal Julio., 2017, 14000000000 CLEARTEX
[7]   pASSWORD tYPOS and How to Correct Them Securely [J].
Chatterjee, Rahul ;
Athalye, Anish ;
Akhawe, Devdatta ;
Juels, Ari ;
Ristenpart, Thomas .
2016 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2016, :799-818
[8]  
Chatterjee Rahul, 2017, ACM C COMP COMM SEC
[9]  
Collins Katie, 2017, FACEBOOK BUYS BLACK
[10]   The Tangled Web of Password Reuse [J].
Das, Anupam ;
Bonneau, Joseph ;
Caesar, Matthew ;
Borisov, Nikita ;
Wang, XiaoFeng .
21ST ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2014), 2014,