Show simple item record

dc.contributor.authorDiomedous, Constantinosen
dc.contributor.authorAthanasopoulos, Eliasen
dc.contributor.editorPerdisci, Robertoen
dc.contributor.editorMaurice, Clémentineen
dc.contributor.editorGiacinto, Giorgioen
dc.contributor.editorAlmgren, Magnusen
dc.coverage.spatialChamen
dc.creatorDiomedous, Constantinosen
dc.creatorAthanasopoulos, Eliasen
dc.date.accessioned2021-01-22T10:47:53Z
dc.date.available2021-01-22T10:47:53Z
dc.date.issued2019
dc.identifier.isbn978-3-030-22038-9
dc.identifier.urihttp://gnosis.library.ucy.ac.cy/handle/7/62489
dc.description.abstractText-based passwords are still the dominant form of user authentication in remote services. Beyond the many usability issues associated with handling several text-based passwords, security is also an important dimension. Through the years, a significant amount of on-line services has been compromised and their stored passwords have been leaked. Once the database is compromised, it takes little time for a program to crack the cryptographically hashed (weak) passwords, no matter the algorithm used.In response to this problem, researchers have proposed cryptographic services for hardening all stored passwords. These services perform several sessions of cryptographic hashing combined with message authentication codes. The goal of these services is to coerce adversaries to use them while cracking the passwords. This essentially transforms off-line password cracking to on-line.Although these services incorporate elaborate cryptographic schemes for password hardening, it is unclear how easily typical web sites can utilize them without outsourcing the functionality to large providers. In this paper, we take a systems approach for making any web site that is serviced through TLS capable of strongly hardening their passwords. We observe that any TLS-enabled web server is already equipped with strong cryptographic functions. We modify mod_ssl, the module that offers TLS to any Apache web server, to act as a password-hardening service. Our evaluation shows that with an overhead similar to adapting hash functions (such as scrypt and bcrypt), our proposal can protect even the weakest passwords, once they are leaked.en
dc.language.isoenen
dc.publisherSpringer International Publishingen
dc.sourceDetection of Intrusions and Malware, and Vulnerability Assessmenten
dc.titlePractical Password Hardening Based on TLSen
dc.typeinfo:eu-repo/semantics/conferenceObject
dc.identifier.doi10.1007/978-3-030-22038-9_21
dc.description.startingpage441
dc.description.endingpage460
dc.author.faculty002 Σχολή Θετικών και Εφαρμοσμένων Επιστημών / Faculty of Pure and Applied Sciences
dc.author.departmentΤμήμα Πληροφορικής / Department of Computer Science
dc.type.uhtypeConference Objecten
dc.contributor.orcidAthanasopoulos, Elias [0000-0002-8759-3261]
dc.gnosis.orcid0000-0002-8759-3261


Files in this item

FilesSizeFormatView

There are no files associated with this item.

This item appears in the following Collection(s)

Show simple item record