Hide metadata

dc.date.accessioned2024-04-30T15:14:41Z
dc.date.created2024-03-13T10:58:08Z
dc.date.issued2024
dc.identifier.citationBüttner, Andre Pedersen, Andreas Thue Wiefling, Stephan Gruschka, Nils Lo Iacono, Luigi . Is It Really You Who Forgot the Password? When Account Recovery Meets Risk-Based Authentication. Ubiquitous Security. 2024 Springer Nature
dc.identifier.urihttp://hdl.handle.net/10852/110676
dc.description.abstractRisk-based authentication (RBA) is used in online services to protect user accounts from unauthorized takeover. RBA commonly uses contextual features that indicate a suspicious login attempt when the characteristic attributes of the login context deviate from known and thus expected values. Previous research on RBA and anomaly detection in authentication has mainly focused on the login process. However, recent attacks have revealed vulnerabilities in other parts of the authentication process, specifically in the account recovery function. Consequently, to ensure comprehensive authentication security, the use of anomaly detection in the context of account recovery must also be investigated. This paper presents the first study to investigate risk-based account recovery (RBAR) in the wild. We analyzed the adoption of RBAR by five prominent online services (that are known to use RBA). Our findings confirm the use of RBAR at Google, LinkedIn, and Amazon. Furthermore, we provide insights into the different RBAR mechanisms of these services and explore the impact of multi-factor authentication on them. Based on our findings, we create a first maturity model for RBAR challenges. The goal of our work is to help developers, administrators, and policy-makers gain an initial understanding of RBAR and to encourage further research in this direction.
dc.languageEN
dc.publisherSpringer Nature
dc.relation.ispartofCommunications in Computer and Information Science (CCIS)
dc.relation.ispartofseriesCommunications in Computer and Information Science (CCIS)
dc.titleIs It Really You Who Forgot the Password? When Account Recovery Meets Risk-Based Authentication
dc.title.alternativeENEngelskEnglishIs It Really You Who Forgot the Password? When Account Recovery Meets Risk-Based Authentication
dc.typeChapter
dc.creator.authorBüttner, Andre
dc.creator.authorPedersen, Andreas Thue
dc.creator.authorWiefling, Stephan
dc.creator.authorGruschka, Nils
dc.creator.authorLo Iacono, Luigi
dc.date.embargoenddate2025-03-13
cristin.unitcode185,15,5,76
cristin.unitnameDigital sikkerhet
cristin.ispublishedtrue
cristin.fulltextpostprint
dc.identifier.cristin2254040
dc.identifier.bibliographiccitationinfo:ofi/fmt:kev:mtx:ctx&ctx_ver=Z39.88-2004&rft_val_fmt=info:ofi/fmt:kev:mtx:book&rft.btitle=Ubiquitous Security&rft.spage=&rft.date=2024
dc.identifier.doihttps://doi.org/10.1007/978-981-97-1274-8_26
dc.type.documentBokkapittel
dc.type.peerreviewedPeer reviewed
dc.source.isbn9789819712748
dc.type.versionAcceptedVersion
cristin.btitleUbiquitous Security


Files in this item

Appears in the following Collection

Hide metadata