User Account Access Graphs
Sven Hammann, Sasa Radomirovic, Ralf Sasse, David A. Basin
摘要
The primary authentication method for a user account is rarely the only way to access that account. Accounts can often be accessed through other accounts, using recovery methods, password managers, or single sign-on. This increases each account's attack surface, giving rise to subtle security problems. These problems cannot be detected by considering each account in isolation, but require analyzing the links between a user's accounts. Furthermore, to accurately assess the security of accounts, the physical world must also be considered. For example, an attacker with access to a physical mailbox could obtain credentials sent by post. Despite the manifest importance of understanding these interrelationships and the security problems they entail, no prior methods exist to perform an analysis thereof in a precise way. To address this need, we introduce account access graphs, the first formalism that enables a comprehensive modeling and analysis of a user's entire setup, incorporating all connections between the user's accounts, devices, credentials, keys, and documents. Account access graphs support systematically identifying both security vulnerabilities and lockout risks in a user's accounts. We give analysis algorithms and illustrate their effectiveness in a case study, where we automatically detect significant weaknesses in a user's setup and suggest improvement options. CCS CONCEPTS • Security and privacy → Formal security models; Authentication.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson 等USENIX Security 2021 · 被引用 42 次
- Asynchronous AuthenticationMarwa Mouallem, Ittay EyalCCS 2024 · 被引用 1 次
- Encrypted Access Logging for Online Accounts: Device Attributions without Device TrackingCarolina Ortega Pérez, Alaa DaffallaUSENIX Security 2025
相关 Paper
- "I'm Surprised So Much Is Connected"Sven Hammann, Michael Crabb, Sasa Radomirovic, Ralf Sasse 等CHI 2022 · 被引用 6 次
- Interactive Multi-Credential AuthenticationDeepak Maram, Mahimna Kelkar, Ittay EyalCCS 2024 · 被引用 1 次
- An Investigation of Identity-Account Inconsistency in Single Sign-OnGuannan Liu, Xing Gao, Haining WangWWW 2021 · 被引用 9 次
- PassREfinder: Credential Stuffing Risk Prediction by Representing Password Reuse between Websites on a GraphJaehan Kim, Minkyoo Song, Minjae Seo, Youngjin Jin 等S&P 2024 · 被引用 8 次
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
