This study conducts an analysis of login throttling mechanisms on both websites and smartphone apps, focusing particularly on 20 large Chinese and non-Chinese services. Our research uniquely addresses discrepancies in authentication strategies between these services, which have not been extensively covered in existing literature. We manually simulate the behavior of persistent attackers who can circumvent common anti-bot measures, such as solving CAPTCHAs and employing non-suspicious IP addresses. Our findings reveal significant variations in CAPTCHA implementation, password guessing restrictions, and the integration of multiple login throttling mechanisms between app and web interfaces. Notably, Chinese services tend to deploy more complex CAPTCHA systems and additional verification, whereas non-Chinese services are more susceptible to continuous guessing attacks. This paper also proposes a procedure for analyzing and comparing the efficacy of authentication measures in mitigating password-based attacks, contributing to future enhancements to security practices for online services.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Towards Exploring Cross-Regional and Cross-Platform Differences in Login Throttling

  • Minjie Cai,
  • Xavier de Carné de Carnavalet,
  • Siqi Zhang,
  • Lianying Zhao,
  • Mengyuan Zhang

摘要

This study conducts an analysis of login throttling mechanisms on both websites and smartphone apps, focusing particularly on 20 large Chinese and non-Chinese services. Our research uniquely addresses discrepancies in authentication strategies between these services, which have not been extensively covered in existing literature. We manually simulate the behavior of persistent attackers who can circumvent common anti-bot measures, such as solving CAPTCHAs and employing non-suspicious IP addresses. Our findings reveal significant variations in CAPTCHA implementation, password guessing restrictions, and the integration of multiple login throttling mechanisms between app and web interfaces. Notably, Chinese services tend to deploy more complex CAPTCHA systems and additional verification, whereas non-Chinese services are more susceptible to continuous guessing attacks. This paper also proposes a procedure for analyzing and comparing the efficacy of authentication measures in mitigating password-based attacks, contributing to future enhancements to security practices for online services.