Anti-hammering mechanisms frequently struggle to manage both Brute Force Attacks (BFAs) and Denial of Service (DoS) attacks effectively, highlighting the need for robust safeguards to counter credential guessing and account lockouts. A pluggable authentication module for e-mail as an additional authentication factor may offer a practical solution but fails to provide an advantage when the same e-mail address resets the primary authentication factor. A thorough literature review reveals no existing module supporting a secondary e-mail address. This technical documentation presents a Lightweight Directory Access Protocol (LDAP)-dependent prototype implemented on a standard Linux Operating System (OS). Each Multi-Factor Authentication (MFA) solution faces inherent vulnerabilities. Therefore, comprehensive threat modeling identifies nine categories of potential weaknesses in the new module, necessitating careful evaluation during deployment.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A Pluggable Authentication Module for E-Mail as a Secure Additional Authentication Factor

  • Günter Fahrnberger

摘要

Anti-hammering mechanisms frequently struggle to manage both Brute Force Attacks (BFAs) and Denial of Service (DoS) attacks effectively, highlighting the need for robust safeguards to counter credential guessing and account lockouts. A pluggable authentication module for e-mail as an additional authentication factor may offer a practical solution but fails to provide an advantage when the same e-mail address resets the primary authentication factor. A thorough literature review reveals no existing module supporting a secondary e-mail address. This technical documentation presents a Lightweight Directory Access Protocol (LDAP)-dependent prototype implemented on a standard Linux Operating System (OS). Each Multi-Factor Authentication (MFA) solution faces inherent vulnerabilities. Therefore, comprehensive threat modeling identifies nine categories of potential weaknesses in the new module, necessitating careful evaluation during deployment.