REVISITING DEFENSES AGAINST LARGE SCALE ONLINE PASSWORD GUESSING ATTACKS
Mansour Alsaleh,Mohammad Mannan and P.C van Oorschot
CONTENTS
INTRODUCTION
AUTOMATED TURING TEST
PASSWORD GUESSING RESISTANT PROTOCOL
FLOWCHART
START
Un,pw,cookie,W,FT,FS
A
If
F 1
B
YES
NO
A
B
If
F2
If
F3
If
F4
If
F5
Else
FS[srcIP,un]=0
Add srcIP to W
FS[srcIP,un]=0
Add srcIP to W
ATTchallenge incorrect
FS[srcIP,un]=FS[srcIP,un]+1
FT[un]=FT[un]+1
ATT challenge is incorrect
If
f6
NO
YES
YES
NO
YES
YES
NO
NO
NO
Un,pw is incorrect
F2—((Valid(cookie,un,k1,true)V((srcIP,un) c w))
(FS[srcIP,un]<k1))
(FT[un]<k2)
F3—(ATTChallenge()=pass)
F4—((Valid(cookie,un,k1,false)V((srcIP,un) c w))
(FS[srcIP,un]<K1)
F5—(validUsername(un)
(FT[un]<k2)
F6—(ATTChallenge()=pass)
F1—LoginCorrect(un,pw)
COOKIES Vs IP ADDRESS
Cookies require browser interface | Same machine might be assigned different IP address |
Login will be difficult if user is using mulitiple browsers | Group of machines may be represented by a single IP address |
Cookies may be deleted | |
DECISION FUNCTION FOR REQUESTING ATTs
The decision to challenge the user with an ATT depends on two factors:
1) whether the user has authenticated successfully from the same machine previously.
2) The total number of failed login attempts for a specific user account.
USERNAME PASSWORD PAIR IS VALID
The user wont be asked to answer an ATT challenge if
USERNAME PASSWORD IS INVALID
User wont be asked to answer ATT challenge if
OUTPUT MESSAGES
PGRP shows messages in case of
WHY NOT TO BLACKLIST OFFENDING IP ADDRESSES?
COMPARISON WITH OTHER ATT BASED PROTOCOLS
Based on 4 questions:
Q1. What is the expected number of passwords that an adversary can eliminate from the password space without answering any ATT challenge?
Q2. What is the expected number of ATT challenges an adversary must answer to correctly guess a password?
Q3. What is the probability of a confirmed correct guess for an adversary unwilling to answer any ATT?
Q4. What is the probability of a confirmed correct guess for an adversary willing to answer c ATTs?
FINDINGS:
Based on 2 questions
Q1. What is the probability that an adversary knowing m usernames can correctly guess a password without answering any ATT challenge?
Q2. What is the probability of a confirmed correct guess for an adversary knowing m usernames and willing to answer c ATTs?
USABILITY COMMENTS ON ATT CHALLENGES
Different scenarios:
SYSTEM RESOURCES
LIMITATIONS
EMPIRICAL EVALUATION
Analysis based on 2 datasets.
ANALYSIS OF RESULT
Done on different perspective.
CONCLUSION
REFERENCES
[1] Amazon Mechanical Turk. https://www.mturk.com/mturk/,
June 2010.
[2] S.M. Bellovin, “A Technique for Counting Natted Hosts,” Proc.
ACM SIGCOMM Workshop Internet Measurement, pp. 267-272,
2002.
[3] E. Bursztein, S. Bethard, J.C. Mitchell, D. Jurafsky, and C.
Fabry, “How Good Are Humans at Solving CAPTCHAs? A
Large Scale Evaluation,” Proc. IEEE Symp. Security and Privacy,
May 2010.
THANK YOU