Examination of a New Defense Mechanism: Honeywords - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2018

Examination of a New Defense Mechanism: Honeywords

Ziya Alper Genç
  • Fonction : Auteur
  • PersonId : 1036542

Résumé

Past experiences show us that password breach is still one of the main methods of attackers to obtain personal or sensitive user data. Basically, assuming they have access to list of hashed passwords, they apply guessing attacks, i.e., attempt to guess a password by trying a large number of possibilities. We certainly need to change our way of thinking and use a novel and creative approach in order to protect our passwords. In fact, there are already novel attempts to provide password protection. The Honeywords system of Juels and Rivest is one of them which provides a detection mechanism for password breaches. Roughly speaking, they propose a method for password-based authentication systems where fake passwords, i.e., “honeywords” are added into a password file, in order to detect impersonation. Their solution includes an auxiliary secure server called “honeychecker” which can distinguish a user’s real password among her honeywords and immediately sets off an alarm whenever a honeyword is used. However, they also pointed out that their system needs to be improved in various ways by highlighting some open problems. In this paper, after revisiting the security of their proposal, we specifically focus on and aim to solve a highlighted open problem, i.e., active attacks where the adversary modifies the code running on either the login server or the honeychecker.
Fichier principal
Vignette du fichier
469589_1_En_8_Chapter.pdf (425.5 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-01875522 , version 1 (17-09-2018)

Licence

Paternité

Identifiants

Citer

Ziya Alper Genç, Süleyman Kardaş, Mehmet Sabir Kiraz. Examination of a New Defense Mechanism: Honeywords. 11th IFIP International Conference on Information Security Theory and Practice (WISTP), Sep 2017, Heraklion, Greece. pp.130-139, ⟨10.1007/978-3-319-93524-9_8⟩. ⟨hal-01875522⟩
318 Consultations
57 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More