User Account Access Graphs
Sven Hammann, Sasa Radomirovic, Ralf Sasse, David A. Basin
Abstract
The primary authentication method for a user account is rarely the only way to access that account. Accounts can often be accessed through other accounts, using recovery methods, password managers, or single sign-on. This increases each account's attack surface, giving rise to subtle security problems. These problems cannot be detected by considering each account in isolation, but require analyzing the links between a user's accounts. Furthermore, to accurately assess the security of accounts, the physical world must also be considered. For example, an attacker with access to a physical mailbox could obtain credentials sent by post. Despite the manifest importance of understanding these interrelationships and the security problems they entail, no prior methods exist to perform an analysis thereof in a precise way. To address this need, we introduce account access graphs, the first formalism that enables a comprehensive modeling and analysis of a user's entire setup, incorporating all connections between the user's accounts, devices, credentials, keys, and documents. Account access graphs support systematically identifying both security vulnerabilities and lockout risks in a user's accounts. We give analysis algorithms and illustrate their effectiveness in a case study, where we automatically detect significant weaknesses in a user's setup and suggest improvement options. CCS CONCEPTS • Security and privacy → Formal security models; Authentication.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3331a693-d3d5-4b4e-acec-bd7d1474b76aCited by top-tier papers3
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson et al.USENIX Security 2021 · 42 citations
- Asynchronous AuthenticationMarwa Mouallem, Ittay EyalCCS 2024 · 1 citation
- Encrypted Access Logging for Online Accounts: Device Attributions without Device TrackingCarolina Ortega Pérez, Alaa DaffallaUSENIX Security 2025
Related papers
- "I'm Surprised So Much Is Connected"Sven Hammann, Michael Crabb, Sasa Radomirovic, Ralf Sasse et al.CHI 2022 · 6 citations
- Interactive Multi-Credential AuthenticationDeepak Maram, Mahimna Kelkar, Ittay EyalCCS 2024 · 1 citation
- An Investigation of Identity-Account Inconsistency in Single Sign-OnGuannan Liu, Xing Gao, Haining WangWWW 2021 · 9 citations
- PassREfinder: Credential Stuffing Risk Prediction by Representing Password Reuse between Websites on a GraphJaehan Kim, Minkyoo Song, Minjae Seo, Youngjin Jin et al.S&P 2024 · 8 citations
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
