Title: A countermeasure algorithm for password guessing attacks

Authors: Adesina S. Sodiya; A.A. Afolorunso; Omoniyi P. Ogunderu

Addresses: Department of Computer Science, University of Agriculture, P.M.B. 2240, Abeokuta, Ogun State, Nigeria. ' School of Science and Technology, National Open University of Nigeria, 14 – 16, Ahmadu Bello Way, Victoria Island, Lagos, Nigeria. ' Department of Computer Science, University of Agriculture, P.M.B. 2240, Abeokuta, Ogun State, Nigeria

Abstract: Password authentication systems, which are used as first level of defence, are not efficient enough to withstand the dynamic techniques of attackers. In this work, an authentication scheme using first trial protocol (FTR protocol) was developed to prevent dictionary and brute force attacks. FTR protocol uses a rule-based reasoning and splits the process of authentication into two layers; first and second layer protocols. The first layer undertakes the validation of the login password against set of recorded invalid passwords in the first layer repository. The second layer is the second line of authentication in another host different from that of first layer containing the protocol and its penalties. 11,000,000 human authentication request data were used to conduct an evaluation experiment. Zero vulnerability was found in the protocol and an efficient value of 97.89% was established as a confidence measure. This shows that the protocol is secured against online password guessing attacks.

Keywords: computer security; password authentication; online passwords; password guessing attacks; dictionary attack; brute force attacks; first trial protocol; FTR protocol.

DOI: 10.1504/IJICS.2011.044824

International Journal of Information and Computer Security, 2011 Vol.4 No.4, pp.345 - 364

Published online: 28 Feb 2015 *

Full-text access for editors Full-text access for subscribers Purchase this article Comment on this article