Is It Really You Who Forgot the Password? When Account Recovery Meets Risk-Based Authentication

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Büttner, Andre, Pedersen, Andreas Thue, Wiefling, Stephan, Gruschka, Nils, Iacono, Luigi Lo
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916164044587008
author Büttner, Andre
Pedersen, Andreas Thue
Wiefling, Stephan
Gruschka, Nils
Iacono, Luigi Lo
author_facet Büttner, Andre
Pedersen, Andreas Thue
Wiefling, Stephan
Gruschka, Nils
Iacono, Luigi Lo
contents Risk-based authentication (RBA) is used in online services to protect user accounts from unauthorized takeover. RBA commonly uses contextual features that indicate a suspicious login attempt when the characteristic attributes of the login context deviate from known and thus expected values. Previous research on RBA and anomaly detection in authentication has mainly focused on the login process. However, recent attacks have revealed vulnerabilities in other parts of the authentication process, specifically in the account recovery function. Consequently, to ensure comprehensive authentication security, the use of anomaly detection in the context of account recovery must also be investigated. This paper presents the first study to investigate risk-based account recovery (RBAR) in the wild. We analyzed the adoption of RBAR by five prominent online services (that are known to use RBA). Our findings confirm the use of RBAR at Google, LinkedIn, and Amazon. Furthermore, we provide insights into the different RBAR mechanisms of these services and explore the impact of multi-factor authentication on them. Based on our findings, we create a first maturity model for RBAR challenges. The goal of our work is to help developers, administrators, and policy-makers gain an initial understanding of RBAR and to encourage further research in this direction.
format Preprint
id arxiv_https___arxiv_org_abs_2403_11798
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Is It Really You Who Forgot the Password? When Account Recovery Meets Risk-Based Authentication
Büttner, Andre
Pedersen, Andreas Thue
Wiefling, Stephan
Gruschka, Nils
Iacono, Luigi Lo
Cryptography and Security
Risk-based authentication (RBA) is used in online services to protect user accounts from unauthorized takeover. RBA commonly uses contextual features that indicate a suspicious login attempt when the characteristic attributes of the login context deviate from known and thus expected values. Previous research on RBA and anomaly detection in authentication has mainly focused on the login process. However, recent attacks have revealed vulnerabilities in other parts of the authentication process, specifically in the account recovery function. Consequently, to ensure comprehensive authentication security, the use of anomaly detection in the context of account recovery must also be investigated. This paper presents the first study to investigate risk-based account recovery (RBAR) in the wild. We analyzed the adoption of RBAR by five prominent online services (that are known to use RBA). Our findings confirm the use of RBAR at Google, LinkedIn, and Amazon. Furthermore, we provide insights into the different RBAR mechanisms of these services and explore the impact of multi-factor authentication on them. Based on our findings, we create a first maturity model for RBAR challenges. The goal of our work is to help developers, administrators, and policy-makers gain an initial understanding of RBAR and to encourage further research in this direction.
title Is It Really You Who Forgot the Password? When Account Recovery Meets Risk-Based Authentication
topic Cryptography and Security
url https://arxiv.org/abs/2403.11798