1.2
Page 3: Authentication
Authentication is the binding of an identity to a subject (a user or an entity).
A user or entity is often required to authenticate itself to a computer system.
When using Internet banking, authentication by the bank site is necessary.
When using email, a password linked to the username or account name is required for authentication.
Page 4: A Digital User Authentication Model
NIST SP 800-63-3 defines a general model for user authentication.
It involves two steps: user registration with the system and authentication.
Page 5: Registration, credential issuance, and maintenance
Registration involves identity proofing, subscriber/registration authority, and user registration claimant.
Credential issuance includes authenticated confirmation assertion and token/credential service.
Maintenance involves relying party, authentication session authority, and validation provider.
Page 6: Means of Authentication
A subject must provide information to confirm its identity.
Information can be something the individual knows (password, PIN, answers to questions), possesses (token), is (static biometrics), or does (dynamic biometrics).
Page 7: Multifactor authentication
Multifactor authentication uses more than one authentication means.
The strength of the system is determined by the number of factors incorporated.
Two factors are considered stronger than one, three factors are stronger than two.
Page 8: Password-based Authentication
Password-based authentication is a simple and common method.
Despite security vulnerabilities, passwords are commonly used for authentication.
A password is information associated with an entity that confirms its identity.
Page 9: How do password systems work?
Account registration can be allocated/set by an administrator.
Passwords should be changed in this case.
Double entry of passwords and confirmation through email are common.
Authentication and reset/update/recover are part of the process.
Page 10: Password Authentication
The user supplies an identity and a password.
The server checks the supplied information.
If the password matches, the user's identity is authenticated; otherwise, the password is rejected.
Page 11: False positives and negatives
False positives and negatives are errors in authentication.
False positives occur when a match is made but shouldn't have.
False negatives occur when a match is not made but should have.
Page 12: False positives and negatives (continued)
False acceptance rate (FAR) is the proportion of authentication attempts resulting in false acceptances.
False positive effects differ in the context of "raising an alarm" from the context of "making a match".
Page 13: False positives and negatives (continued)
False rejection rate (FRR) is the proportion of authentication attempts resulting in false rejections.
Page 14: FAR and FRR
FAR and FRR are possible in authentication mechanisms with tolerance in matching.
Initially, with no tolerance, these rates default to zero.
FAR becomes relevant when storing transformed passwords.
Cryptographic hash functions are used for this purpose.
Page 15: Threats against password systems
Password guessing, exposure, login Trojan programs, and poor passwords are threats.
Common attacks include dictionary attacks, brute force attacks, and hybrid attacks.
Compromise of the password file can occur online or offline.
Page 16: Password guessing
It is always possible to attempt to guess a password online.
Guessing the password of a user on Capa by trying to login as that user is a common method.
Depending on the authentication mechanism, the data sent to the server may not be the actual password.
Page 17: Password exposure
Passwords can be seen by eavesdroppers when typed.
Writing passwords down or sharing them with others is a security risk.
Trust assumptions are critical in security.
Page 18: Login Trojan Horses
Login Trojan Horses produce genuine login screens but capture passwords.
The captured information is stored for malicious purposes.
Protection lies in not installing the Trojan Horse in the first place.
Page 19: Poor password
Users often choose simple passwords for ease of remembering.
Many systems enforce restrictions on the passwords allowed.
Page 20: Poor passwords โ Dictionary attacks
Password requirements may allow dictionary words.
Dictionary attacks use sets of common words to try as passwords.
This attack is fast but may not always succeed.
Page 21: Tailored dictionary attacks
Dictionaries can be specific to a theme (e.g., car brands, sports teams).
Users may use personal information like birthdates or family names for passwords.
Page 22: Brute force
All password systems are vulnerable to guessing the correct password.
Brute force attacks involve trying every possible password.
Changing passwords regularly makes it harder to guess.
Page 23: Choosing secure passwords
The time to test the correct password depends on the size of the password space and the number of passwords that can be tested per second.
Randomly generated passwords with a large character set are secure but hard to remember.
Using an arbitrary password over a larger character set increases security.
Page 24: Password entropy
Entropy is related to information content, randomness, and uncertainty.
Entropy is often measured in bits.
The entropy for N equally likely options is log2N.
Page 25: Example: compute password's entropy
The password is generated with specific criteria.
The password's entropy needs to be computed.
Page 26: Example: compute password's entropy
The password space is computed by determining the number of possible passwords for each character group.
The total number of possible passwords is calculated.
The entropy is determined using the formula log2N.
Page 27: Trying to improve passwords
Pronounceable passwords make it easier to remember passwords.
Using pass-phrases with intentional misspellings, odd capitalizations, and symbol replacements can enhance password security.
Page 28: Hybrid attacks
Hybrid attacks combine elements of dictionary attacks and brute force attacks.
Variants of words tested in a dictionary are used.
Characters can be replaced with numbers or symbols.
Page 29: Personal phrase based: Helping memory?
Choosing a phrase and taking the first letter from each word can help with password memorization.
Using well-known phrases is not recommended due to the risk of dictionary attacks.
Page 30: Protective mechanisms
Tracking incorrect password attempts can help identify potential intruders.
Limiting the number of guesses per connection attempt or locking the account after a threshold is exceeded can deter attackers.
Slowly processing passwords can slow down attackers.
Page 31: "Online" versus "Offline" guessing
Online guessing faces restrictions on the number of attempts, while offline attacks do not.
Offline attacks can occur if an intruder accesses the password file or intercepts the transmission of a password.
Communication security and cryptography are covered in other courses.
Page 32
The distinction between "online" and "offline" guessing is not as important as the restriction on the number of guesses.
Attackers will operate differently based on the guessing restrictions.
Page 33: Rules for password systems
Examples of rules for password systems are provided.
Passwords should be changed regularly, have a minimum length, and include a mix of characters.
Dictionary words should be avoided, and previous passwords should not be reused.
Failed logon attempts can result in temporary account lockouts.
Page 34: UOW password rules
The University of Wollongong has specific password rules.
Passwords must meet certain length and character requirements.
Personal information and compromised passwords are not allowed.
Page 35: Protecting passwords
Password repositories must be well protected.
In UNIX, only hashes of passwords are stored.
Hashing makes it computationally infeasible to find the associated password.
Page 36: What is hashing?
Hashing is a procedure used for message integrity and indexing.
Hashing reduces the computational overhead of digital signatures.
The hash of a message is a fixed-length fingerprint of the data block.
Page 37: Hash Functions
Hash functions transform data into a fixed short length.
The hash value of a message can be efficiently computed.
The output is referred to as the hash value or message digest.
Page 39: Cryptographic Hash Functions
Cryptographic hash functions have additional properties.
One-way or pre-image resistance makes it computationally infeasible to find the original message from the hash.
Collision resistance makes it computationally infeasible to find different messages with the same hash.
Page 41
MD5 and SHA-1 are hash algorithms.
MD5 produces a 128-bit message digest.
SHA-1 produces a 160-bit message digest and uses the design approach used in MD5.
Both MD5 and SHA-1 are broken with respect to collisions.
Collision resistance is harder to achieve than pre-image resistance.
Page 42
Additional sources on hash function security and encryption:
Wikipedia page on hash function security summary
NIST policy on hash functions
Street Directory article on MD5, SHA-1, and SHA-2
FreeCodeCamp article on secure encryption hash
Jscrambler blog post on hashing algorithms
Page 43
Passwords are not directly stored in UNIX, only their hash is stored.
The password file is encrypted using a system-known password.
The password is inputted during system boot.
Salting is used to further protect the hash.
Page 44
Password salting involves using a random or pseudo-random value called a salt.
The hash of the salt and password combination is stored.
The salt value is also stored.
Page 45
The salt prevents duplicate passwords from being visible in the password file.
Different salt values for the same password result in different hashed passwords.
Salting increases the difficulty of offline dictionary attacks.
A salt of length b bits increases the number of possible passwords by a factor of 2^b.
It becomes nearly impossible to determine if a person has used the same password on multiple systems.
Page 48
Hash collisions can lead to false positives in password acceptance.
The likelihood of collisions is very low.
Page 49
Early versions of UNIX stored user IDs and transformed passwords in the /etc/passwd file.
The /etc/passwd file contained user ID, encrypted password, home directory, and default shell information.
Page 50
The general format of the passwd file includes fields for username, transformed password, UID, GID, full name, home directory, and shell.
Page 51
UNIX split the passwd file information into two files: passwd and shadow.
The passwd file contains everything except the protected passwords.
The shadow file contains the transformed passwords and is only accessible to the root user.
Page 52
Storing password hashes in shadow files is the preferred method.
The /etc/passwd file should not store password hashes.
The /etc/passwd and /etc/shadow files contain corresponding username and transformed password pairs.
Page 53
Shadow files have fields for username, transformed password, last password change date, minimum and maximum password change days, warning days, expiration days, and disable days.
Page 54
Using shadow files is safer than before, but there are still vulnerabilities.
Attackers need a valid user ID and password to break into a system.
Valid user IDs can be obtained from the /etc/passwd file.
Password guessing attacks can be launched.
Shadow files require root access, but there were attacks that allowed acquiring the shadow file without root access.
Certain servers like imapd and telnet were guilty of dumping core with the shadow file in a user-readable format.
Rainbow Tables
Pre-computation can speed up an attack
Rainbow tables are lookup tables of passwords and corresponding hash values
Extended versions use hashing and reduction functions for smaller lookup tables
Reduction Functions
Map hash output space back into password space
Table construction involves hashing and reducing passwords in sequences called hash chains
Table Lookup
Check hash value in the table
If not found, reduce and hash until it appears
Found value indicates the password to start from
Hash, reduce, and hash until the original hash value is reached
The preceding password is the desired one
One-time Passwords
User and system have a list of valid passwords, each valid only once
Immune to eavesdropping and leaked passwords reveal no information
Problems include the number of passwords to be shared and stored, significant initial costs, and increased storage for the server
Lamport's One-time Password
User remembers a password, server stores username, counter, and hash value
Authentication protocol involves exchanging information and checking hash values
Server updates information after successful authentication
Alice and Bob
Common names used to represent participants in cryptographic protocols
Other cryptographic identities include Eve, Mel, Oscar, Peggy, Victor, etc.
Token-based Authentication
Tokens are objects used for user authentication
Two types: memory cards and smart cards
Memory Cards
Can store but not process data
Examples include bank cards and hotel room cards
Authentication requires both the memory card and a password or PIN
Adversary needs physical possession and knowledge of the PIN
Smart Cards
Include an embedded microprocessor
Can have manual or electronic interfaces
Provide means for user authentication through static or dynamic password generation or challenge-response
Contains ROM, EEPROM, and RAM memory types
Biometric Authentication
Should be used as a component of a multi-factor authentication system
Biometrics are not private and are used to make attacks more difficult
Face recognition, handwriting, fingerprints, iris codes, voice recognition, and DNA are types of biometrics
Iris codes are considered the most robust, but still have some problems
provides a rough indication of the cost and accuracy of biometric measures.