Secure web applications against off-line password guessing attack : a two way password protocol with challenge response using arbitrary images

dc.contributor.advisorZou, Xukai, 1963-
dc.contributor.authorLu, Zebin
dc.contributor.otherLiang, Yao
dc.contributor.otherFang, Shiaofen
dc.contributor.otherLi, Feng
dc.date.accessioned2013-08-14T16:15:54Z
dc.date.available2013-08-14T16:15:54Z
dc.date.issued2013-08-14
dc.degree.date2012en_US
dc.degree.disciplineDepartment of Computer and Information Scienceen_US
dc.degree.grantorPurdue Universityen_US
dc.degree.levelM.S.en_US
dc.descriptionIndiana University-Purdue University Indianapolis (IUPUI)en_US
dc.description.abstractThe web applications are now being used in many security oriented areas, including online shopping, e-commerce, which require the users to transmit sensitive information on the Internet. Therefore, to successfully authenticate each party of web applications is very important. A popular deployed technique for web authentication is the Hypertext Transfer Protocol Secure (HTTPS) protocol. However the protocol does not protect the careless users who connect to fraudulent websites from being trapped into tricks. For example, in a phishing attack, a web user who connects to an attacker may provide password to the attacker, who can use it afterwards to log in the target website and get the victim’s credentials. To prevent phishing attacks, the Two-Way Password Protocol (TPP) and Dynamic Two-Way Password Protocol (DTPP) are developed. However there still exist potential security threats in those protocols. For example, an attacker who makes a fake website may obtain the hash of users’ passwords, and use that information to arrange offline password guessing attacks. Based on TPP, we incorporated challenge responses with arbitrary images to prevent the off-line password guessing attacks in our new protocol, TPP with Challenge response using Arbitrary image (TPPCA). Besides TPPCA, we developed another scheme called Rain to solve the same problem by dividing shared secrets into several rounds of negotiations. We discussed various aspects of our protocols, the implementation and experimental results.en_US
dc.identifier.urihttps://hdl.handle.net/1805/3425
dc.identifier.urihttp://dx.doi.org/10.7912/C2/2302
dc.language.isoen_USen_US
dc.subjectWeb Securityen_US
dc.subject.lcshWeb sites -- Security measuresen_US
dc.subject.lcshWorld Wide Web -- Security measuresen_US
dc.subject.lcshComputer network protocols -- Standardsen_US
dc.subject.lcshComputer hackersen_US
dc.subject.lcshComputers -- Access control -- Passwordsen_US
dc.subject.lcshInternet -- Security measuresen_US
dc.subject.lcshPhishing -- Security measuresen_US
dc.titleSecure web applications against off-line password guessing attack : a two way password protocol with challenge response using arbitrary imagesen_US
Files
Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
144288_pdf_135215_ADE067F0-9B09-11E1-9A48-DB3CEF8616FA.pdf
Size:
547.44 KB
Format:
Adobe Portable Document Format
Description:
Main article
License bundle
Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.88 KB
Format:
Item-specific license agreed upon to submission
Description: