A Pluggable Authentication Module for E-Mail as a Secure Additional Authentication Factor
摘要
Anti-hammering mechanisms frequently struggle to manage both Brute Force Attacks (BFAs) and Denial of Service (DoS) attacks effectively, highlighting the need for robust safeguards to counter credential guessing and account lockouts. A pluggable authentication module for e-mail as an additional authentication factor may offer a practical solution but fails to provide an advantage when the same e-mail address resets the primary authentication factor. A thorough literature review reveals no existing module supporting a secondary e-mail address. This technical documentation presents a Lightweight Directory Access Protocol (LDAP)-dependent prototype implemented on a standard Linux Operating System (OS). Each Multi-Factor Authentication (MFA) solution faces inherent vulnerabilities. Therefore, comprehensive threat modeling identifies nine categories of potential weaknesses in the new module, necessitating careful evaluation during deployment.