DocumentCode :
2923659
Title :
Safeguarding academic accounts and resources with the University Credential Abuse Auditing System
Author :
Zhang, Jing ; Berthier, Robin ; Rhee, Will ; Bailey, Michael ; Pal, Partha ; Jahanian, Farnam ; Sanders, William H.
Author_Institution :
Dept. of Electr. Eng. & Comput. Sci., Univ. of Michigan, Ann Arbor, MI, USA
fYear :
2012
fDate :
25-28 June 2012
Firstpage :
1
Lastpage :
8
Abstract :
Whether it happens through malware or through phishing, loss of one´s online identity is a real and present danger. While many attackers seek credentials to realize financial gain, an analysis of the compromised accounts at our own institutions reveals that perpetrators often steal university credentials to gain free and unfettered access to information. This nontraditional motivation for credential theft puts a special burden on the academic institutions that provide these accounts. In this paper, we describe the design, implementation, and evaluation of a system for safeguarding academic accounts and resources called the University Credential Abuse Auditing System (UCAAS). We evaluate UCAAS at two major research universities with tens of thousands of user accounts and millions of login events during a two-week period. We show the UCAAS to be useful in reducing this burden, having helped the university security teams identify a total of 125 compromised accounts with zero false positives during the trail.
Keywords :
Internet; auditing; computer crime; educational administrative data processing; educational institutions; invasive software; Internet; UCAAS; academic accounts safeguarding; academic institutions; academic resources safeguarding; credential theft; data theft; financial gain; login events; malware; online identity; phishing; university credential abuse auditing system; user accounts; Authentication; Educational institutions; IP networks; Libraries; Training; Virtual private networks; Virtual Private Network (VPN); authentication; compromised account; university;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks (DSN), 2012 42nd Annual IEEE/IFIP International Conference on
Conference_Location :
Boston, MA
ISSN :
1530-0889
Print_ISBN :
978-1-4673-1624-8
Electronic_ISBN :
1530-0889
Type :
conf
DOI :
10.1109/DSN.2012.6263961
Filename :
6263961
Link To Document :
بازگشت