Identity management refers to the technology and policies for the identification, authentication, and authorization of users in computer networks. Identity management is therefore fundamental to today's IT ecosystem. At the same time, identity management systems, where digital identities are managed, pose an attractive target for attacks. With the heterogeneity of identity management systems, every type (i.e., models, protocols, implementations) has different requirements, typical problems, and hence attack vectors. In order to provide a systematic and categorized overview, the framework Taxonomy for Identity Management Attacks (TaxIdMA) for attacks related to identities is proposed. The purpose of this framework is to classify existing attacks associated with system identities, identity management systems, and end-user identities as well as the background using an extensible structure from a scientific perspective. The taxonomy is then evaluated with eight real-world attacks resp. vulnerabilities. This analysis shows the capability of the proposed taxonomy framework TaxIdMA in describing and categorizing these attacks.
翻译:身份管理是指计算机网络用户的识别、认证和授权技术和政策,因此身份管理是当今信息技术生态系统的根本所在,同时,管理数字身份的身份管理系统是一个具有吸引力的攻击目标,随着身份管理系统的多样性,每种类型(即模式、协议、实施)都有不同的要求、典型问题,因此也是攻击矢量。为了提供系统和分类的概览,提出了身份管理攻击的分类框架(TaxIdMA),用于与身份有关的攻击。这一框架的目的是从科学角度对与系统身份、身份管理系统和最终用户身份有关的现有攻击进行分类,并利用可扩展的结构进行背景分析,然后用八个真实世界攻击的弱点来评价分类。这一分析显示了拟议的身份管理攻击分类框架(TaxIdMA)在描述和分类这些攻击时的能力。