How effective is multifactor authentication at deterring cyberattacks?

05/01/2023
by   Lucas Augusto Meyer, et al.
0

This study investigates the effectiveness of multifactor authentication (MFA) in protecting commercial accounts from unauthorized access, with an additional focus on accounts with known credential leaks. We employ the benchmark-multiplier method, coupled with manual account review, to evaluate the security performance of various MFA methods in a large dataset of Microsoft Azure Active Directory users exhibiting suspicious activity. Our findings reveal that MFA implementation offers outstanding protection, with over 99.99 of MFA-enabled accounts remaining secure during the investigation period. Moreover, MFA reduces the risk of compromise by 99.22 population and by 98.56 that dedicated MFA applications, such as Microsoft Authenticator, outperform SMS-based authentication, though both methods provide significantly enhanced security compared to not using MFA. Based on these results, we strongly advocate for the default implementation of MFA in commercial accounts to increase security and mitigate unauthorized access risks.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
06/16/2023

Lost and not Found: An Investigation of Recovery Methods for Multi-Factor Authentication

Multi-Factor Authentication is intended to strengthen the security of pa...
research
02/28/2019

Ratio-Balanced Maximum Flows

When a loan is approved for a person or company, the bank is subject to ...
research
03/18/2019

The epidemiology of lateral movement: exposures and countermeasures with network contagion models

An approach is developed for analyzing computer networks to identify sys...
research
03/08/2019

A Novel Approach for Protection of Accounts' Names against Hackers Combining Cluster Analysis and Chaotic Theory

The last years of the 20 th century and the beginning of the 21 th mark ...
research
05/26/2021

Evaluation of Account Recovery Strategies with FIDO2-based Passwordless Authentication

Threats to passwords are still very relevant due to attacks like phishin...
research
09/01/2023

"Make Them Change it Every Week!": A Qualitative Exploration of Online Developer Advice on Usable and Secure Authentication

Usable and secure authentication on the web and beyond is mission-critic...
research
05/15/2023

European 5G Security in the Wild: Reality versus Expectations

5G cellular systems are slowly being deployed worldwide delivering the p...

Please sign up or login with your details

Forgot password? Click here to reset