A countermeasure algorithm for password guessing attacks
by Adesina S. Sodiya; A.A. Afolorunso; Omoniyi P. Ogunderu
International Journal of Information and Computer Security (IJICS), Vol. 4, No. 4, 2011

Abstract: Password authentication systems, which are used as first level of defence, are not efficient enough to withstand the dynamic techniques of attackers. In this work, an authentication scheme using first trial protocol (FTR protocol) was developed to prevent dictionary and brute force attacks. FTR protocol uses a rule-based reasoning and splits the process of authentication into two layers; first and second layer protocols. The first layer undertakes the validation of the login password against set of recorded invalid passwords in the first layer repository. The second layer is the second line of authentication in another host different from that of first layer containing the protocol and its penalties. 11,000,000 human authentication request data were used to conduct an evaluation experiment. Zero vulnerability was found in the protocol and an efficient value of 97.89% was established as a confidence measure. This shows that the protocol is secured against online password guessing attacks.

Online publication date: Sat, 28-Feb-2015

The full text of this article is only available to individual subscribers or to users at subscribing institutions.

 
Existing subscribers:
Go to Inderscience Online Journals to access the Full Text of this article.

Pay per view:
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Information and Computer Security (IJICS):
Login with your Inderscience username and password:

    Username:        Password:         

Forgotten your password?


Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.

If you still need assistance, please email subs@inderscience.com