Skip to main navigation Skip to search Skip to main content

Knocking on Admin’s Door: Protecting Critical Web Applications with Deception

  • Stony Brook University

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

2 Scopus citations

Abstract

In this paper, we introduce PageKnocker, a deception-based supplementary authentication mechanism, aimed primarily at protecting the public-facing authentication endpoints of critical web applications. PageKnocker is inspired by the network security concept of port knocking, and uses the requests to the web application as a means of authentication for the login page. Specifically, the authentication is successful (i.e. the user gets to access the login page of a web application), if the user’s request sequence matches their personal predefined request sequence. In this manner, PageKnocker offers web application administrators the comparative advantage of knowing the nature of a visitor even before that visitor sends the first set of credentials. Alongside PageKnocker, we introduce two deceptive login environments, one overtly deceptive and one clandestine, towards which we direct any unauthenticated user attempting to reach the real login page. To evaluate the security and usability of page knocks, we deploy PageKnocker-protected honeypots in the wild and perform a separate user study, showing that PageKnocker can resist tens of thousands of brute-forcing bots, while remaining usable and intuitive.

Original languageEnglish
Title of host publicationDetection of Intrusions and Malware, and Vulnerability Assessment - 21st International Conference, DIMVA 2024, Proceedings
EditorsFederico Maggi, Manuel Egele, Mathias Payer, Michele Carminati
PublisherSpringer Science and Business Media Deutschland GmbH
Pages283-306
Number of pages24
ISBN (Print)9783031641701
DOIs
StatePublished - 2024
Event21st International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2024 - Lausanne, Switzerland
Duration: Jul 17 2024Jul 19 2024

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume14828 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference21st International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2024
Country/TerritorySwitzerland
CityLausanne
Period07/17/2407/19/24

Fingerprint

Dive into the research topics of 'Knocking on Admin’s Door: Protecting Critical Web Applications with Deception'. Together they form a unique fingerprint.

Cite this