SMS-based second factor authentication is a cornerstone for many service providers, ranging from email service providers and social networks to financial institutions and online marketplaces. Attackers have not been slow to capitalize on the vulnerabilities of this mechanism by using social engineering techniques to coerce users to forward authentication codes. We demonstrate one social engineering attack for which we experimentally obtained a 50% success rate against Google’s SMS-based authentication. At the heart of the problem is the messaging associated with the authentication code, and how this must not have been developed with security against social engineering in mind. Pursuing a top-down methodology, we generate alternative messages and experimentally test these against an array of social engineering attempts. Our most robust messaging approach reduces the success of the most effective social engineering attack to 8%, or a sixth of its success against Google’s standard second factor verification code messages. H. Siadati Google LLC, Infrastructure and Cloud, New York, NY, USA T. Nguyen Department of Security R&D, Salesforce.com Inc., San Francisco, CA, USA P. Gupta Pindrop, Atlanta, GA, USA M. Jakobsson ( ) ZapFraud Inc., Portola Valley, CA, USA N. Memon New York University, Computer Science and Engineering, Brooklyn, NY, USA © The Editor(s) (if applicable) and The Author(s), under exclusive license to Springer Nature Switzerland AG 2020 M. Jakobsson (ed.), Security, Privacy and User Interaction, https://doi.org/10.1007/978-3-030-43754-1_1 5
SMS-based second factor authentication is a cornerstone for many service providers, ranging from email service providers and social networks to financial institutions and online marketplaces. Attackers have not been slow to capitalize on the vulnerabilities of this mechanism by using social engineering techniques to coerce users to forward authentication codes. We demonstrate one social engineering attack for which we experimentally obtained a 50% success rate against Google's SMS-based authentication. At the heart of the problem is the messaging associated with the authentication code, and how this must not have been developed with security against social engineering in mind. Pursuing a top-down methodology, we generate alternative messages and experimentally test these against an array of social engineering attempts. Our most robust messaging approach reduces the success of the most effective social engineering attack to 8%, or a sixth of its success against Google's standard second factor verification code messages.
Attackers increasingly, and with high success rates, use social engineering techniques to circumvent second factor authentication (2FA) technologies, compromise user accounts and sidestep fraud detection technologies. We introduce a social engineering resistant approach that we term device-aware 2FA, to replace the use of traditional security codes.
Human failure is the weakest link in many, if not most, security systems. As a result, criminals are increasingly relying on social engineering as a way to circumvent security controls. To improve their yield, criminals constantly experiment with methods aimed at making their attacks harder to detect-both to security systems and to the end users behind them. Naturally, an attack that successfully ...
More than ten years ago, a devastating data substitution attack was shown to successfully compromise all previously proposed remote attestation techniques. In fact, the authors went further than simply attacking previously proposed methods: they called into question whether it is theoretically possible for remote attestation methods to exist in face of their attack. Subsequently, it has been shown that it is possible, by relying on self-modifying code. We show that it is possible to create remote attestation that is secure against all data substitution attacks, without relying on self-modifying code. Our proposed method relies on a construction of the checksum process that forces frequent L2 cache overflows if any data substitution
The forensic investigation of communication datasets which contain unstructured text, social network information, and metadata is a complex task that is becoming more important due to the immense amount of data being collected. Currently there are limited approaches that allow an investigator to explore the network, text and metadata in a unified manner. We developed Beagle as a forensic tool for email datasets that allows investigators to flexibly form complex queries in order to discover important information in email data. Beagle was successfully deployed at a security firm which had a large email dataset that was difficult to properly investigate. We discuss our experience developing Beagle as well as the lessons we learned applying visual analytic techniques to a difficult real-world problem.
There are countless ways to carry out a cyber-attack, but in the vast majority the key is deception – typically involving identity deception in which the attacker poses as a trusted party to the intended victim. Many of these attacks involve stealing passwords from victims in order to access their accounts and pose as them. Therefore, with cyber-criminals constantly on the prowl to capture passwords and other credentials, two-factor authentication (2FA) has become one of the most widely accepted back-up verifications for many services and companies. With cyber-criminals constantly on the prowl to capture passwords and other credentials, two-factor authentication (2FA) has become one of the most widely accepted back-up verifications for many services and companies. However, as Markus Jakobsson of Agari points out, 2FA has its own issues. Other options are on the way, but it's more important than ever for organisations to be aware that their workforce's digital identities may be compromised.
We demonstrate a vulnerability in existing content-based message filtering methods, showing how an attacker can use a simple obfuscator to modify any message to a homograph version of the same message, thereby avoiding digest and signature based detection methods. We measure the success of this potential attack against Hotmail, Gmail and Yahoo mail. While the attack is bothersome both in terms of its simplicity and its success, it is also easily countered. We describe some computationally practical countermeasures.
Deception is rapidly on the rise on the Internet, and email is the attack vector of choice for a broad array of attacks, including ransomware distribution, enterprise-facing cons, and mass-deployed phishing attacks. It is widely believed that this is due to the ubiquity of email and the limited extent to which relevant email security measures have been rolled out. The most troubling type of attack is the targeted attack, in which the attacker poses as somebody the intended victim knows. There are three common ways used by attackers to masquerade as somebody trusted: spoofing, look-alike domain attacks and display name attacks. We collectively refer to these as impersonation attacks.
We describe a novel approach to reduce the impact of spoofing by a subtle change in the login process. At the heart of our contribution is the understanding that current anti-spoof technologies fail largely as a result of the difficulties to communicate security and risk to typical users. Accordingly, our solution is oblivious to whether the user was tricked by a fraudster or not. We achieve that by modifying the user login process, and letting the browser or operating system cause different results of user login requests, based on whether the site is trusted or not. Experimental results indicate that our new approach, which we dub “SpoofKiller”, will address approximately 80% of spoofing attempts.
Sid Stamm合作论文数Mozilla10
Ryusuke Masuoka合作论文数6
Steven A. Myers合作论文数Center for Applied Cybersecurity Research4
Ruj Akavipat合作论文数Indiana University3