Pump Up Password Security! Evaluating and Enhancing Risk-Based Authentication on a Real-World Large-Scale Online Service
arXiv:2206.15139 · doi:10.1145/3546069
Abstract
Risk-based authentication (RBA) aims to protect users against attacks involving stolen passwords. RBA monitors features during login, and requests re-authentication when feature values widely differ from previously observed ones. It is recommended by various national security organizations, and users perceive it more usable and equally secure than equivalent two-factor authentication. Despite that, RBA is still only used by very few online services. Reasons for this include a lack of validated open resources on RBA properties, implementation, and configuration. This effectively hinders the RBA research, development, and adoption progress. To close this gap, we provide the first long-term RBA analysis on a real-world large-scale online service. We collected feature data of 3.3 million users and 31.3 million login attempts over more than one year. Based on the data, we provide (i) studies on RBA's real-world characteristics, and its configurations and enhancements to balance usability, security, and privacy, (ii) a machine learning based RBA parameter optimization method to support administrators finding an optimal configuration for their own use case scenario, (iii) an evaluation of the round-trip time feature's potential to replace the IP address for enhanced user privacy, and (iv) a synthesized RBA data set to reproduce this research and to foster future RBA research. Our results provide insights on selecting an optimized RBA configuration so that users profit from RBA after just a few logins. The open data set enables researchers to study, test, and improve RBA for widespread deployment in the wild.
35 pages, 18 figures, 7 tables. Data set awarded with Open Data Impact Award 2022 by the German Stifterverband
References in corpus (5)
- More Than Just Good Passwords? A Study on Usability and Security Perceptions of Risk-based Authentication
- Privacy Considerations for Risk-Based Authentication Systems
- Evaluation of Risk-based Re-Authentication Methods
- VerLoc: Verifiable Localization in Decentralized Systems
- Secure Client and Server Geolocation Over the Internet
Cited by in corpus (4)
- Evaluation of Real-World Risk-Based Authentication at Online Services Revisited: Complexity Wins
- Is It Really You Who Forgot the Password? When Account Recovery Meets Risk-Based Authentication
- Towards an Improved Taxonomy of Attacks related to Digital Identities and Identity Management Systems
- A Privacy Measure Turned Upside Down? Investigating the Use of HTTP Client Hints on the Web