Title
Rethinking about guessing attacks
Abstract
Although various past efforts have been made to characterize and detect guessing attacks, there is no consensus on the definition of guessing attacks. Such a lack of generic definition makes it extremely difficult to evaluate the resilience of security protocols to guessing attacks. To overcome this hurdle, we seek a new definition in this paper to fully characterize the attacker's guessing capabilities (i.e., guessability). This provides a general framework to reason about guessing attacks in a symbolic setting, independent of specific intruder models. We show how the framework can be used to analyze both passive and active guessing attacks.
Year
DOI
Venue
2011
10.1145/1966913.1966954
computer and communications security
Keywords
Field
DocType
specific intruder model,generic definition,various past effort,general framework,security protocol,symbolic setting,new definition,attack,one time password
Psychological resilience,Internet privacy,Cryptographic protocol,Computer security,Computer science,One-time password
Conference
Citations 
PageRank 
References 
0
0.34
39
Authors
2
Name
Order
Citations
PageRank
Zhiwei Li11315107.73
Weichao Wang250033.87