USENIX Security2020Top-tier venue
Detecting Stuffing of a User's Credentials at Her Own Accounts
Ke Coby Wang, Michael K. Reiter
Abstract
We propose a framework by which websites can coordinate to detect credential stuffing on individual user accounts. Our detection algorithm teases apart normal login behavior (involving password reuse, entering correct passwords into the wrong sites, etc.) from credential stuffing, by leveraging modern anomaly detection and carefully tracking suspicious logins. Websites coordinate using a novel private membership-test protocol, thereby ensuring that information about passwords is not leaked; this protocol is highly scalable, partly due to its use of cuckoo filters, and is more secure than similarly scalable alternatives in an important measure that we define. We use probabilistic model checking to estimate our credential-stuffing detection accuracy across a range of operating points. These methods might be of independent interest for their novel application of formal methods to estimate the usability impacts of our design. We show that even a minimal-infrastructure deployment of our framework should already support the combined login load experienced by the airline, hotel, retail, and consumer banking industries in the U.S.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5617b225-38fe-4f95-a3a5-07f23116d3dcCited by top-tier papers9
- Private Blocklist Lookups with ChecklistDmitry Kogan, Henry Corrigan-GibbsUSENIX Security 2021 · 104 citations
- Using Amnesia to Detect Credential Database BreachesKe Coby Wang, Michael K. ReiterUSENIX Security 2021 · 18 citations
- Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password AuthenticationSena Sahin, Frank LiCCS 2021 · 13 citations
- The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern WebBehzad Ousat, Esteban Schafir, Duc C. Hoang, Mohammad Ali Tofighi et al.WWW 2024 · 11 citations
- Flock: A Framework for Deploying On-Demand Distributed TrustDarya Kaviani, Sijun Tan, Pravein Govindan Kannan, Raluca Ada PopaOSDI 2024 · 5 citations
Builds on12
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio et al.NDSS 2016 · 151 citations
- Malicious-Secure Private Set Intersection via Dual ExecutionPeter Rindal, Mike RosulekCCS 2017 · 135 citations
Related papers
- How to End Password Reuse on the WebKe Coby Wang, Michael K. ReiterNDSS 2019 · 49 citations
- PassREfinder: Credential Stuffing Risk Prediction by Representing Password Reuse between Websites on a GraphJaehan Kim, Minkyoo Song, Minjae Seo, Youngjin Jin et al.S&P 2024 · 8 citations
- Protocols for Checking Compromised CredentialsLucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan et al.CCS 2019 · 80 citations
- Might I Get Pwned: A Second Generation Compromised Credential Checking ServiceBijeeta Pal, Mazharul Islam, Marina Sanusi Bohuk, Nick Sullivan et al.USENIX Security 2022
- Detecting Structurally Anomalous Logins Within Enterprise NetworksHossein Siadati, Nasir D. MemonCCS 2017 · 44 citations
