[论文解读] How effective is multifactor authentication at deterring cyberattacks?
本研究使用基准乘数法和对 Microsoft Azure Active Directory 中可疑登录尝试的手动审查,评估了多因素认证(MFA)在保护商业账户方面的有效性。研究发现,MFA 总体将账户被攻破的风险降低了 99.22%,即使在凭证泄露的情况下,风险仍降低 98.56%。专用应用程序(如 Microsoft Authenticator)的表现优于短信(SMS)。
This study investigates the effectiveness of multifactor authentication (MFA) in protecting commercial accounts from unauthorized access, with an additional focus on accounts with known credential leaks. We employ the benchmark-multiplier method, coupled with manual account review, to evaluate the security performance of various MFA methods in a large dataset of Microsoft Azure Active Directory users exhibiting suspicious activity. Our findings reveal that MFA implementation offers outstanding protection, with over 99.99% of MFA-enabled accounts remaining secure during the investigation period. Moreover, MFA reduces the risk of compromise by 99.22% across the entire population and by 98.56% in cases of leaked credentials. We further demonstrate that dedicated MFA applications, such as Microsoft Authenticator, outperform SMS-based authentication, though both methods provide significantly enhanced security compared to not using MFA. Based on these results, we strongly advocate for the default implementation of MFA in commercial accounts to increase security and mitigate unauthorized access risks.
研究动机与目标
- 评估多因素认证(MFA)在现实企业环境中保护商业账户免受未授权访问的实际效果。
- 比较不同 MFA 方法(特别是 SMS 与专用应用程序如 Microsoft Authenticator)在大规模企业环境中的安全性能。
- 评估在用户凭证已被泄露这一高风险场景下,MFA 的有效性。
- 使用统计上稳健的抽样方法,量化 MFA 在商业工作负载中提供的风险降低程度。
- 基于其高保护效能的实证证据,倡导在商业账户中默认启用 MFA。
提出的方法
- 采用基准乘数法,估算在大量 Microsoft Azure Active Directory 用户群体中账户被攻破的总数量。
- 使用 1,525 个被标记为可疑活动的代表性样本,估算总体的账户被攻破率。
- 应用偏差校正估计技术,以调整被攻破账户与总账户比例中的非线性关系。
- 对每种类别执行 1,000 次蒙特卡洛模拟,生成估计被攻破率的 95% 置信区间。
- 对 128,000 个已知凭证泄露的账户进行手动审查,以在真实攻击条件下验证 MFA 的有效性。
- 使用类似于疫苗有效性的公式计算风险降低率:1 -(启用 MFA 后的被攻破率 / 未启用 MFA 的被攻破率)
实验结果
研究问题
- RQ1在真实世界的企业环境中,多因素认证(MFA)在防止商业账户未授权访问方面的有效性如何?
- RQ2在针对自动化攻击和定向攻击时,不同 MFA 方法(特别是 SMS 与专用移动应用如 Microsoft Authenticator)的相对有效性如何?
- RQ3在用户凭证已因数据泄露而暴露的情况下,MFA 对账户的保护效果如何?
- RQ4MFA 在整个商业账户群体中,能在多大程度上降低账户被攻破的整体风险?
- RQ5若已启用 MFA,估计有多少比例的被攻破账户本可得到保护?
主要发现
- MFA 在整个商业账户群体中,将账户被攻破的风险降低了 99.22%。
- 在已知凭证泄露的账户中,MFA 将被攻破风险降低了 98.56%,表明即使在高风险条件下仍具有极强的韧性。
- 超过 99.99% 的启用 MFA 的账户在调查期间保持安全,表明在所观察到的威胁环境下,其保护效果近乎完美。
- 专用 MFA 应用程序(如 Microsoft Authenticator)的失败率仅为 0.97%–0.99%,显著优于 SMS 的 1.66% 失败率。
- 在防止针对泄露凭证账户的攻击方面,基于 SMS 的 MFA 效果比 Microsoft Authenticator 低 40.8%。
- 缺乏 MFA 的被攻破账户占比为 99.17%,证实 MFA 在真实世界数据泄露场景中是主导性的防护控制措施。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。