We design and implement a novel communications latency based authentication scheme, dubbed CLAS, that strengthens the security of state-of-the-art web authentication approaches by leveraging the round trip network communications latency (RTL) between clients and authenticators. In addition to the traditional credentials, CLAS profiles RTL values of clients and uses them to defend against password compromise. The key challenges are (i) to prevent RTL manipulation, (ii) to alleviate network instabilities, and (iii) to address mobile clients. CLAS addresses the first challenge by introducing a novel network architecture, which makes it extremely difficult for attackers to simulate legitimate RTL values. The second challenge is addressed by outlier removal and multiple temporal profiling, while the last challenge is addressed by augmenting CLAS with out-of-band-channels or other authentication schemes. CLAS restricts login to profiled locations while demanding additional information for nonprofiled ones, which highly reduces the attack surface even when the legitimate credentials are compromised. Additionally, unlike many state-of-the-art authentication mechanisms, CLAS is resilient to phishing, pharming, man-in-the-middle, and social engineering attacks. Furthermore, CLAS is transparent to users and incurs negligible overhead. The experimental results show that CLAS can achieve very low false positive and false negative rates.
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2rR6Ahj
via IFTTT
Εγγραφή σε:
Σχόλια ανάρτησης (Atom)
Δημοφιλείς αναρτήσεις
-
Through the Wormhole: Is There an Edge to... Science - 43 min - ★ It is commonly theorized that the universe began with the Big Bang... Thro...
-
Web version of a book about Subversion. Work in progress, however already very complete. The book should be published by O'Reilly and As...
-
by Kerstin Jost, Isabelle Pramana, Edgar Delgado-Eckert, Nitin Kumar, Alexandre N. Datta, Urs Frey, Sven M. Schulzke Background Poor contro...
-
by Rita Rey-Baños, Luis E. Sáenz de Miera, Pedro García, Marcelino Pérez de la Vega Retrotransposons with long terminal repeats (LTR-RTs) a...
-
from #AlexandrosSfakianakis via Alexandros G.Sfakianakis on Inoreader http://ift.tt/2nL9dMr via IFTTT
-
Summary We tested whether prophylactic droperidol and ondansetron, in combination with a moderate dose of dexamethasone, were equally effe...
-
http://ift.tt/2p7HgAl
-
by Demin Li, Carol Bentley, Jenna Yates, Maryam Salimi, Jenny Greig, Sarah Wiblin, Tasneem Hassanali, Alison H. Banham Therapeutic monoclon...
-
How to write a Scholarship Essay - Examples. Scholarship Essays should use this formatting unless specified otherwise: Two to three pages in...
Δεν υπάρχουν σχόλια:
Δημοσίευση σχολίου