The proposed novel password reset standard performs authentication and password update in a single cryptographically bound flow, eliminating the need for sessions, cookies, OTPs, or email-based verification, and mitigating phishing, session hijacking, CSRF, and replay attacks.
Abstract
SSH remains a critical yet heavily targeted protocol for remote system administration, with password-based authentication exposing servers to large-scale brute-force, dictionary, and credential-spray attacks. Existing rule-based defences such as Fail2Ban fail to detect slow, distributed, or threshold-aware adversaries, while conventional account-recovery mechanisms: email links, OTPs, and out-of-band verification introduce additional vulnerabilities including phishing, session hijacking, and weak authentication binding. This work presents SSHafe, a real-time SSH brute-force detection and mitigation system that combines time-series feature engineering with a lightweight LightGBM classifier to identify attack patterns directly from system authentication logs. A multi-scale sliding-window approach extracts behavioural features such as attempt rates, inter-arrival times, failure ratios, and username diversity, enabling the model to achieve a detection accuracy of 99.96% on benchmark data and strong performance on unlabeled real-world traffic. Upon detecting an attack, SSHafe automatically blocks the targeted user account and delivers an SSH banner guiding legitimate users to a novel passkey-based password-rotation workflow. The proposed novel password reset standard performs authentication and password update in a single cryptographically bound flow, eliminating the need for sessions, cookies, OTPs, or email-based verification, and mitigating phishing, session hijacking, CSRF, and replay attacks. Experiments on an Azure VM and live adversarial traffic demonstrate that SSHafe can identify and suppress brute-force activity within ten seconds, preventing account compromise even with weak credentials.
A hybrid browser-resident phishing detection framework that combines three complementary detection mechanisms: a locally executed Random Forest model using URL lexical features, lightweight real-time DOM structure analysis, and VirusTotal’s multi-engine reputation service is proposed.
Muhammad Arshad, Beena Sherin Kuriakose, C. W. Onn et al.· Frontiers of Computer Scienc...· 0 citations
Threat-Reactive Encryption (TRE), a four-layer framework that couples a real-time ML threat scorer to a PKCS#11-compatible key management pipeline, closing the gap between threat detection and cryptographic response, is presented.
Mohammed El-hajj· International Conference on...· 0 citations
This work proposes a self-calibrating side-channel attack (SC-SCA) that enables high-accuracy HMAC-SM3 key recovery using only a single power trace during the attack phase, and provides both a practical security benchmark for CPSS edge devices and theoretical foundations for designing side-channel-resistant cryptographic implementations.
Zhen Wu, Zhiguang Qin, Kai Wang· Frontiers of Physics· 0 citations
Cloud services lingers to transfigure information management and computation, it also presents momentous sanctuary apprehensions—predominantly in terms of identifying user credentials and secure information handling in decentralized networks. Outdated text-based access control mechanisms and even enhanced identity verification methods repeatedly fail to meet expectations in counter to advanced cyberattacks such as phishing schemes, identity compromise and session manipulations. To challenge these complications, this research presents an advanced, math-driven sanctuary prototype precisely premeditated for safe cloud computation. The projected model integrates three critical components: (1) data-level packet chunking, (2) AES-based encryption enhanced by a Dynamic Permutation Matrix (DPM), and (3) a new behaviour-driven authentication system called Behaviour-Linked One-Time Challenge (BLOC). This AI-powered validation technique powers behavioural biometrics such as typing undercurrents and mouse movement forms for safe and adaptive user proof. By uniting coarse data fortification and smart verification, the projected outline boosts privacy, veracity, and access control inside the cloud growth, offering greater flexibility against contemporary attack trajectories while upholding performance and scalability.
B. Sowmya, Meeravali Shaik· International journal of com...· 0 citations
Password-based authentication is one of the most fundamental vulnerabilities of enterprise information systems. This vulnerability is exploited through phishing, credential stuffing, password reuse and real-time transmission attacks where an attacker intercepts data. With strong multi-factor authentication, the risk is minimized but human-mediated factors like SMS, time-based OTP, confirmation notifications may get affected through fake login pages and reverse proxy. In general, the paper presents an evaluation of the security, usability, recovery, governance and interoperability aspects of FIDO2/WebAuthn and passkey which to be used for enterprise authentication. As per standards and current research, the study is qualitative risk comparison of password, password+OTP, push MFA, device-bound passkey and synchronized passkey approach; it establishes threat-control mapping; and proposes Enterprises five-phase migration. Consequently, as the proof demonstrates, this passkey approach is distinctively architecturally more secure against phishing owing to its root binding, public-key cryptography and authenticator domain. Nonetheless, reliance on synchronization provider, account recovery processes, legacy applications, multi-user-device usage, loss of devices, and enterprise attestation requirements generate new clusters of risks. The framework will consist of the following phases: inventory and user segmentation; pilot implementation for high-risk accounts; rollout to the managed workforce; and recovery and telemetry optimisation towards a managed de-risking against passwords. According to the research, the deployment of passkeys should not merely be regarded as a new technology for logging in. When used, a passkey can be thought of as a comprehensive enterprise security programme that jointly transforms the identity lifecycle, help desk, device management, access policies, and incident response.
Oğuzhan Kilim· International Journal For Mu...· 0 citations
Nowadays, millions of users rely on various types of two-factor authentication (2FA) to secure their accounts in Web 3.0 decentralized and sensitive applications (hereafter referred to as (D)Apps), such as cryptocurrency wallets. Standard user-to-device (U2D) authentication schemes aim to prevent account compromise by requiring one or more verifiable factors. Technically, these credentials can be stolen under certain adversarial scenarios via a device (e.g., an advanced persistent threat enabled by an unpatched vulnerability). To address this issue, this paper proposes a novel explainable Artificial Intelligence (AI)-based dynamic U2D scheme, named Web3U2D, that combines a broad-learning hint generation algorithm based on a bidirectional long short-term memory approach with an attention mechanism. Our proposed scheme enables users to set and memorize multiple secret factors, such as a 4-digit hidden PIN (HPIN) and a 4-symbolic hidden password (HP), during the registration phase. Then, considering an AI-generated hint item, the user must remember two hidden credentials and find two one-time-valid combinations from four selective lists of newly randomized entryways, without typing them at each authentication attempt, thereby preventing the exposure of users’ original combinations. Our results confirm that the Web3U2D approach offers superior performance compared to state-of-the-art schemes based on standard evaluation metrics.
Milad Taleby Ahvanooey, Jun Zhao, Wojciech Mazurczyk· ACM Transactions on Software...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.