Risk-Based Authentication for OpenStack: A Fully Functional Implementation and Guiding Example

03/22/2023
by   Vincent Unsel, et al.
0

Online services have difficulties to replace passwords with more secure user authentication mechanisms, such as Two-Factor Authentication (2FA). This is partly due to the fact that users tend to reject such mechanisms in use cases outside of online banking. Relying on password authentication alone, however, is not an option in light of recent attack patterns such as credential stuffing. Risk-Based Authentication (RBA) can serve as an interim solution to increase password-based account security until better methods are in place. Unfortunately, RBA is currently used by only a few major online services, even though it is recommended by various standards and has been shown to be effective in scientific studies. This paper contributes to the hypothesis that the low adoption of RBA in practice can be due to the complexity of implementing it. We provide an RBA implementation for the open source cloud management software OpenStack, which is the first fully functional open source RBA implementation based on the Freeman et al. algorithm, along with initial reference tests that can serve as a guiding example and blueprint for developers.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/04/2023

Privacy Considerations for Risk-Based Authentication Systems

Risk-based authentication (RBA) extends authentication mechanisms to mak...
research
08/09/2021

Technical Report on a Virtual CTAP2 WebAuthn Authenticator

Even though passwordless authentication to online accounts offers greate...
research
03/17/2020

Is This Really You? An Empirical Study on Risk-Based Authentication Applied in the Wild

Risk-based authentication (RBA) is an adaptive security measure to stren...
research
09/01/2023

"Make Them Change it Every Week!": A Qualitative Exploration of Online Developer Advice on Usable and Secure Authentication

Usable and secure authentication on the web and beyond is mission-critic...
research
10/16/2019

"Get a Free Item Pack with Every Activation!" – Do Incentives Increase the Adoption Rates of Two-Factor Authentication?

Account security is an ongoing issue in practice. Two-Factor Authenticat...
research
06/30/2022

Pump Up Password Security! Evaluating and Enhancing Risk-Based Authentication on a Real-World Large-Scale Online Service

Risk-based authentication (RBA) aims to protect users against attacks in...
research
08/29/2023

Evaluation of Real-World Risk-Based Authentication at Online Services Revisited: Complexity Wins

Risk-based authentication (RBA) aims to protect end-users against attack...

Please sign up or login with your details

Forgot password? Click here to reset