Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
1
Ev Eval aluat ation of
- f Ri
Ev Eval aluat ation of of Ri Risk-base based Re Re-Au - - PowerPoint PPT Presentation
Ev Eval aluat ation of of Ri Risk-base based Re Re-Au Authenticat ation Me Meth thods Stephan Wiefling* # , Tanvi Patil + , Markus Drmuth # , Luigi Lo Iacono* H-BRS University of Applied Sciences (*) Ruhr University Bochum ( # ) UNC
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
1
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
2
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
3
l Weaknesses in password-based
l Large-scale password database leaks
l Credential Stuffing
l Intelligent password guessing* l Phishing
*D. Wang et al.: Targeted online password guessing: An underestimated threat. In CCS ’16. ACM (2016)
Akamai: Credential Stuffing: Attacks and Economies. In: [state of the internet] / security, vol. 5 (2019)
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
4
l 2F
l <10%
*Milka, G.: Anatomy of Account Takeover. In: Enigma 2018. USENIX (Jan 2018)
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
5
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
6
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
7
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
8
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
9
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
10
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
11
l Recommended by NIST digital identity
l Used by large online services[2] l More usable than comparable 2FA methods[3]
[1] Grassi et al.: Digital identity guidelines. Tech. Rep. NIST SP 800-63b (2017) [2] Wiefling et al.: Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the
[3] Wiefling et al.: More Than Just Good Passwords? A Study on Usability and Security Perceptions of Risk-based Authentication. In: ACSAC ’20. ACM (2020)
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
12
l Email verification l Six digit code
l Major impact on time exposure and
l But not studied so far! *Wiefling et al.: Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the Wild. In: IFIP SEC ‘19. Springer (2019)
Se Servic ice Re Requested authentic icatio ion factors Ama Amazon § Ve Verificat ation code (em email*, text message) Fa Faceb ebook
§ Approve login on another computer § Identify photos of friends § Asking friends for help § Ve Verificat ation code (text message) GO GOG. G.com § Ve Verificat ation code (em email)* Go Google § Enter the city you usually sign in from § Ve Verificat ation code (em email, text message, app, phone call) § Press confirmation button on second device Li Linke kedIn § Ve Verificat ation code (em email)*
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
13
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
14
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
15
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
16
l Re-Authentication requested l Method differed in each condition
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
17
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
18
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
19
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
20
*Based on Google‘s Android device confirmation dialog
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
21
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
22
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
23
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
24
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
25
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
26
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
27
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
28
l Median:
l No significant differences between devices
l Median:
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
29
l Code-based: Desktop PC for login + authentication l Link-based: Desktop PC for login, mobile device for authentication
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
30
l Desktop PC for login + authentication (p=0.02)
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
31
*Question similar to Golla et al. (CCS ‘18)
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
32
State of the art (Code in body) Link-based Code in body + subject line
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
33
l Link-based method made users significantly more anxious than code-based
p=0.02 State of the art (Code in body) Link-based
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
34
l Code in subject line and body made significantly less nervous
State of the art (Code in body) Code in body + subject line p=0.03
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
35
l Code in subject line significantly more neutral (p=0.04)
State of the art (Code in body)
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
36
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
37
l Code in subject and body performed
l Faster re-authentication time l Significantly less nervous
l Link-based method:
l Re-authentication time did not
l More anxious when perceived for first
Maribor, Slovenia | IFIP SEC 2020
Stephan Wiefling, Tanvi Patil, Markus Dürmuth, Luigi Lo Iacono
38