Volltext-Downloads (blau) und Frontdoor-Views (grau)
The search result changed since you submitted your search request. Documents might be displayed in a different sort order.
  • search hit 18 of 1266
Back to Result List

What's in Score for Website Users: A Data-Driven Long-Term Study on Risk-Based Authentication Characteristics

  • Risk-based authentication (RBA) aims to strengthen password-based authentication rather than replacing it. RBA does this by monitoring and recording additional features during the login process. If feature values at login time differ significantly from those observed before, RBA requests an additional proof of identification. Although RBA is recommended in the NIST digital identity guidelines, it has so far been used almost exclusively by major online services. This is partly due to a lack of open knowledge and implementations that would allow any service provider to roll out RBA protection to its users. To close this gap, we provide a first in-depth analysis of RBA characteristics in a practical deployment. We observed N=780 users with 247 unique features on a real-world online service for over 1.8 years. Based on our collected data set, we provide (i) a behavior analysis of two RBA implementations that were apparently used by major online services in the wild, (ii) a benchmark of the features to extract a subset that is most suitable for RBA use, (iii) a new feature that has not been used in RBA before, and (iv) factors which have a significant effect on RBA performance. Our results show that RBA needs to be carefully tailored to each online service, as even small configuration adjustments can greatly impact RBA's security and usability properties. We provide insights on the selection of features, their weightings, and the risk classification in order to benefit from RBA after a minimum number of login attempts.

Download full text files

Export metadata

Additional Services

Search Google Scholar Check availability

Statistics

Show usage statistics
Metadaten
Document Type:Conference Object
Language:English
Author:Stephan WieflingORCiD, Markus Dürmuth, Luigi Lo IaconoORCiD
Parent Title (English):Borisov, Diaz (Eds.): Financial Cryptography and Data Security (FC '21). 25th International Conference, FC 2021, Virtual Event, March 1–5, 2021, Revised Selected Papers, Part II. Lecture Notes in Computer Science, vol 12675
First Page:361
Last Page:381
ISBN:978-3-662-64330-3
URN:urn:nbn:de:hbz:1044-opus-59566
DOI:https://doi.org/10.1007/978-3-662-64331-0_19
Publisher:Springer
Place of publication:Berlin, Heidelberg
Publishing Institution:Hochschule Bonn-Rhein-Sieg
Date of first publication:2021/10/23
Copyright:© IFCA. Post-proceedings version of a paper accepted for FC 2021.
Funding:This research was supported by the research training group “Human Centered Systems Security” (NERD.NRW) sponsored by the state of North Rhine-Westphalia. The Platform for Scientific Computing was supported by the German Ministry for Education and Research, and the Ministry for Culture and Science of the state North Rhine-Westphalia (research grant 13FH156IN6).
Keyword:Authentication features; Big Data Analysis; Risk-based Authentication (RBA); Usable Security
Departments, institutes and facilities:Fachbereich Informatik
Dewey Decimal Classification (DDC):0 Informatik, Informationswissenschaft, allgemeine Werke / 00 Informatik, Wissen, Systeme / 005 Computerprogrammierung, Programme, Daten
Entry in this database:2021/10/15
Licence (Multiple languages):License LogoIn Copyright (Urheberrechtsschutz)