Towards Fortifying the Multi-Factor-Based Online Account Ecosystem

04/17/2021
by   Weizhao Jin, et al.
0

With the rapid growth of online services, the number of online accounts proliferates. The security of a single user account no longer depends merely on its own service provider but also the accounts on other service platforms(We refer to this online account environment as Online Account Ecosystem). In this paper, we first uncover the vulnerability of Online Account Ecosystem, which stems from the defective multi-factor authentication (MFA), specifically the ones with SMS-based verification, and dependencies among accounts on different platforms. We propose Chain Reaction Attack that exploits the weakest point in Online Account Ecosystem and can ultimately compromise the most secure platform. Furthermore, we design and implement ActFort, a systematic approach to detect the vulnerability of Online Account Ecosystem by analyzing the authentication credential factors and sensitive personal information as well as evaluating the dependency relationships among online accounts. We evaluate our system on hundreds of representative online services listed in Alexa in diversified fields. Based on the analysis from ActFort, we provide several pragmatic insights into the current Online Account Ecosystem and propose several feasible countermeasures including the online account exposed information protection mechanism and the built-in authentication to fortify the security of Online Account Ecosystem.

READ FULL TEXT

page 1

page 5

page 6

page 8

research
06/26/2023

Your Code is 0000: An Analysis of the Disposable Phone Numbers Ecosystem

Short Message Service (SMS) is a popular channel for online service prov...
research
06/16/2023

Lost and not Found: An Investigation of Recovery Methods for Multi-Factor Authentication

Multi-Factor Authentication is intended to strengthen the security of pa...
research
01/03/2018

New Directions for Trust in the Certificate Authority Ecosystem

Many of the benefits we derive from the Internet require trust in the au...
research
05/17/2022

How Not to Handle Keys: Timing Attacks on FIDO Authenticator Privacy

This paper presents a timing attack on the FIDO2 (Fast IDentity Online) ...
research
02/22/2022

Seeing is Living? Rethinking the Security of Facial Liveness Verification in the Deepfake Era

Facial Liveness Verification (FLV) is widely used for identity authentic...
research
02/28/2019

Ratio-Balanced Maximum Flows

When a loan is approved for a person or company, the bank is subject to ...
research
11/14/2019

Arguing Ecosystem Values with Paraconsistent Logics

The valuation of ecosystem services prompts dialogical settings where no...

Please sign up or login with your details

Forgot password? Click here to reset