USENIX Security2021Top-tier venue
Using Amnesia to Detect Credential Database Breaches
Ke Coby Wang, Michael K. Reiter
Abstract
Known approaches for using decoy passwords (honeywords) to detect credential database breaches suffer from the need for a trusted component to recognize decoys when entered in login attempts, and from an attacker's ability to test stolen passwords at other sites to identify user-chosen passwords based on their reuse at those sites. Amnesia is a framework that resolves these difficulties. Amnesia requires no secret state to detect the entry of honeywords and additionally allows a site to monitor for the entry of its decoy passwords elsewhere. We quantify the benefits of Amnesia using probabilistic model checking and the practicality of this framework through measurements of a working implementation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- The Impact of Exposed Passwords on Honeyword EfficacyZonghao Huang, Lujo Bauer, Michael K. ReiterUSENIX Security 2024 · 7 citations
- Stealing Trust: Unraveling Blind Message Attacks in Web3 AuthenticationKailun Yan, Xiaokuan Zhang, Wenrui DiaoCCS 2024 · 5 citations
- Bernoulli HoneywordsKe Coby Wang, Michael K. ReiterNDSS 2024
- Detecting Compromise of Passkey Storage on the CloudMazharul Islam, Sunpreet S. Arora, Rahul Chatterjee, Ke Coby WangUSENIX Security 2025
Builds on11
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan et al.NDSS 2018 · 1,102 citations
- Fast Private Set Intersection from Homomorphic EncryptionHao Chen, Kim Laine, Peter RindalCCS 2017 · 446 citations
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
- Mobile Private Contact Discovery at ScaleDaniel Kales, Christian Rechberger, Thomas Schneider, Matthias Senker et al.USENIX Security 2019 · 157 citations
Related papers
- Detecting Stuffing of a User's Credentials at Her Own AccountsKe Coby Wang, Michael K. ReiterUSENIX Security 2020
- How to Attack and Generate HoneywordsDing Wang, Yunkai Zou, Qiying Dong, Yuanming Song et al.S&P 2022 · 45 citations
- How to End Password Reuse on the WebKe Coby Wang, Michael K. ReiterNDSS 2019 · 49 citations
- Gossamer: Securely Measuring Password-based LoginsMarina Sanusi Bohuk, Mazharul Islam, Suleman Ahmad, Michael M. Swift et al.USENIX Security 2022
- PassREfinder: Credential Stuffing Risk Prediction by Representing Password Reuse between Websites on a GraphJaehan Kim, Minkyoo Song, Minjae Seo, Youngjin Jin et al.S&P 2024 · 8 citations
