2021
DOI: 10.1007/978-3-662-64331-0_19
|View full text |Cite
|
Sign up to set email alerts
|

What’s in Score for Website Users: A Data-Driven Long-Term Study on Risk-Based Authentication Characteristics

Abstract: Risk-based authentication (RBA) aims to strengthen password-based authentication rather than replacing it. RBA does this by monitoring and recording additional features during the login process. If feature values at login time differ significantly from those observed before, RBA requests an additional proof of identification. Although RBA is recommended in the NIST digital identity guidelines, it has so far been used almost exclusively by major online services. This is partly due to a lack of open knowledge an… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

3
91
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
1
1

Relationship

2
4

Authors

Journals

citations
Cited by 16 publications
(94 citation statements)
references
References 35 publications
3
91
0
Order By: Relevance
“…We answered the questions with the collected data. Two of the following research questions (RQ1a and RQ1c) replicate a related study [70], while the other research questions aim at enhancing our understanding of RBA on a large online service.…”
Section: Research Uestions and Contributionsmentioning
confidence: 98%
See 4 more Smart Citations
“…We answered the questions with the collected data. Two of the following research questions (RQ1a and RQ1c) replicate a related study [70], while the other research questions aim at enhancing our understanding of RBA on a large online service.…”
Section: Research Uestions and Contributionsmentioning
confidence: 98%
“…This is done by monitoring and recording a set of features that are available in the login context. Potential features range from network (e.g., IP address), device or client (e.g., user agent string), to behavioral biometric information (e.g., login time) [70]. Based on the feature values of the current login attempt and those of previous ones stored in a login history, RBA calculates a risk score related to the login attempt.…”
Section: Risk-based Authentication (Rba)mentioning
confidence: 99%
See 3 more Smart Citations