12
IRUS TotalDownloads
Altmetric
A logic-based reasoner for discovering authentication vulnerabilities between interconnected accounts
File | Description | Size | Format | |
---|---|---|---|---|
KarafiliSL18.pdf | Accepted version | 233.38 kB | Adobe PDF | View/Open |
Title: | A logic-based reasoner for discovering authentication vulnerabilities between interconnected accounts |
Authors: | Karafili, E Sgandurra, D Lupu, E |
Item Type: | Conference Paper |
Abstract: | With users being more reliant on online services for their daily activities, there is an increasing risk for them to be threatened by cyber-attacks harvesting their personal information or banking details. These attacks are often facilitated by the strong interconnectivity that exists between online accounts, in particular due to the presence of shared (e.g., replicated) pieces of user information across different accounts. In addition, a significant proportion of users employs pieces of information, e.g. used to recover access to an account, that are easily obtainable from their social networks accounts, and hence are vulnerable to correlation attacks, where a malicious attacker is either able to perform password reset attacks or take full control of user accounts. This paper proposes the use of verification techniques to analyse the possible vulnerabilities that arises from shared pieces of information among interconnected online accounts. Our primary contributions include a logic-based reasoner that is able to discover vulnerable online accounts, and a corresponding tool that provides modelling of user ac- counts, their interconnections, and vulnerabilities. Finally, the tool allows users to perform security checks of their online accounts and suggests possible countermeasures to reduce the risk of compromise. |
Issue Date: | 24-Nov-2018 |
Date of Acceptance: | 27-Jul-2018 |
URI: | http://hdl.handle.net/10044/1/63153 |
ISSN: | 0302-9743 |
Publisher: | Springer Verlag |
Start Page: | 73 |
End Page: | 87 |
Journal / Book Title: | Lecture Notes in Computer Science |
Volume: | 11263 |
Copyright Statement: | © Springer Nature Switzerland AG 2018. he final publication is available at Springer via https://link.springer.com/chapter/10.1007/978-3-030-04372-8_7 |
Sponsor/Funder: | Commission of the European Communities Engineering & Physical Science Research Council (E Engineering & Physical Science Research Council (EPSRC) |
Funder's Grant Number: | 746667 EP/N023242/1 EP/L022729/1 |
Conference Name: | 1st International Workshop on Emerging Technologies for Authorization and Authentication |
Keywords: | Logic-Based Reasoner Logic Analyzer Authentication Interconnected Accounts Artificial Intelligence & Image Processing |
Publication Status: | Published |
Start Date: | 2018-09-03 |
Conference Place: | Barcelona, Spain |
Online Publication Date: | 2018-11-24 |
Appears in Collections: | Computing Faculty of Engineering |