Skip to main navigation Skip to search Skip to main content

Morellian analysis for browsers: Making web authentication stronger with canvas fingerprinting

  • Helmholtz Center for Information Security
  • Campus de Beaulieu
  • KTH Royal Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

24 Scopus citations

Abstract

In this paper, we present the first fingerprinting-based authentication scheme that is not vulnerable to trivial replay attacks. Our proposed canvas-based fingerprinting technique utilizes one key characteristic: it is parameterized by a challenge, generated on the server side. We perform an in-depth analysis of all parameters that can be used to generate canvas challenges, and we show that it is possible to generate unique, unpredictable, and highly diverse canvas-generated images each time a user logs onto a service. With the analysis of images collected from more than 1.1 million devices in a real-world large-scale experiment, we evaluate our proposed scheme against a large set of attack scenarios and conclude that canvas fingerprinting is a suitable mechanism for stronger authentication on the web.

Original languageEnglish
Title of host publicationDetection of Intrusions and Malware, and Vulnerability Assessment - 16th International Conference, DIMVA 2019, Proceedings
EditorsRoberto Perdisci, Roberto Perdisci, Clémentine Maurice, Giorgio Giacinto, Magnus Almgren
PublisherSpringer Verlag
Pages43-66
Number of pages24
ISBN (Print)9783030220372
DOIs
StatePublished - 2019
Event16th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2019 - Gothenburg, Sweden
Duration: Jun 19 2019Jun 20 2019

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume11543 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference16th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2019
Country/TerritorySweden
CityGothenburg
Period06/19/1906/20/19

Fingerprint

Dive into the research topics of 'Morellian analysis for browsers: Making web authentication stronger with canvas fingerprinting'. Together they form a unique fingerprint.

Cite this