"Guess Who ?" Large-Scale Data-Centric Study of the Adequacy of Browser Fingerprints for Web Authentication

05/19/2020
by   Nampoina Andriamilanto, et al.
0

Browser fingerprinting consists in collecting attributes from a web browser to build a browser fingerprint. In this work, we assess the adequacy of browser fingerprints as an authentication factor, on a dataset of 4,145,408 fingerprints composed of 216 attributes. It was collected throughout 6 months from a population of general browsers. We identify, formalize, and assess the properties for browser fingerprints to be usable and practical as an authentication factor. We notably evaluate their distinctiveness, their stability through time, their collection time, and their size in memory. We show that considering a large surface of 216 fingerprinting attributes leads to an 81.8 fingerprints are known to evolve, but we observe that between consecutive fingerprints, more than 90 months. Fingerprints are also affordable. On average, they weight a dozen of kilobytes, and are collected in a few seconds. We conclude that browser fingerprints are a promising additional web authentication factor.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/16/2020

A Large-scale Empirical Analysis of Browser Fingerprints Properties for Web Authentication

Modern browsers give access to several attributes that can be collected ...
research
10/13/2020

FPSelect: Low-Cost Browser Fingerprints for Mitigating Dictionary Attacks against Web Authentication Mechanisms

Browser fingerprinting consists into collecting attributes from a web br...
research
04/19/2021

BrFAST: a Tool to Select Browser Fingerprinting Attributes for Web Authentication According to a Usability-Security Trade-off

In this demonstration, we put ourselves in the place of a website manage...
research
07/11/2023

A Blockchain-based two Factor Honeytoken Authentication System

This paper extends and advances our recently introduced two-factor Honey...
research
09/26/2022

Characteristics and Main Threats about Multi-Factor Authentication: A Survey

This work reports that the Systematic Literature Review process is respo...
research
08/07/2018

Learning-Aided Physical Layer Authentication as an Intelligent Process

Performance of the existing physical layer authentication schemes could ...

Please sign up or login with your details

Forgot password? Click here to reset