{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,29]],"date-time":"2025-12-29T18:50:22Z","timestamp":1767034222978,"version":"3.40.3"},"publisher-location":"Cham","reference-count":46,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030868895"},{"type":"electronic","value":"9783030868901"}],"license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021]]},"DOI":"10.1007\/978-3-030-86890-1_6","type":"book-chapter","created":{"date-parts":[[2021,9,17]],"date-time":"2021-09-17T00:49:44Z","timestamp":1631839784000},"page":"97-115","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Analyzing the Security of OTP 2FA in the Face of Malicious Terminals"],"prefix":"10.1007","author":[{"given":"Ahmed Tanvir","family":"Mahdad","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammed","family":"Jubur","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nitesh","family":"Saxena","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2021,9,17]]},"reference":[{"key":"6_CR1","unstructured":"Outlook- free personal email and calender from microsoft (2020). https:\/\/outlook.live.com\/owa\/"},{"key":"6_CR2","doi-asserted-by":"publisher","unstructured":"Adams, C.: Dictionary Attack, pp. 332. Springer, Boston (2011). https:\/\/doi.org\/10.1007\/978-1-4419-5906-5_74","DOI":"10.1007\/978-1-4419-5906-5_74"},{"key":"6_CR3","unstructured":"Amazon.com Inc: Amazon.com: Online shopping for electronics, apparels, computer, books & dvd and more (2020). https:\/\/www.amazon.com"},{"key":"6_CR4","unstructured":"Anise, O., Lady, K.: State of the auth: experiences and perceptions of multi-factor authentication. Duo security (2017)"},{"key":"6_CR5","unstructured":"AO Kaspersky Lab: Kaspersky security cloud - free (2020). https:\/\/www.kaspersky.com\/free-cloud-antivirus"},{"key":"6_CR6","unstructured":"AV-TEST - The independent IT Security Institute: Malware statistics & trends report (2020). https:\/\/www.av-test.org\/en\/statistics\/malware"},{"key":"6_CR7","unstructured":"Avast Foundation: Avast free antivirus (2020). https:\/\/www.avast.com\/en-us"},{"key":"6_CR8","unstructured":"Avast Software s.r.o.: Avg free antivirus (2020). https:\/\/www.avg.com\/en-us\/"},{"key":"6_CR9","unstructured":"Avira Operations GmbH & Co. KG.: Avira antivirus (2020). https:\/\/www.avira.com\/"},{"key":"6_CR10","doi-asserted-by":"crossref","unstructured":"Bhushan, B., Sahoo, G., Rai, A.K.: Man-in-the-middle attack in wireless and computer networking \u2013 a review. In: 2017 3rd International Conference on Advances in Computing, Communication Automation (ICACCA) (Fall), pp. 1\u20136 (2017)","DOI":"10.1109\/ICACCAF.2017.8344724"},{"key":"6_CR11","unstructured":"Bitdefender: Bitdefender - global leader in cybersecurity software (2020). https:\/\/www.bitdefender.com\/"},{"key":"6_CR12","doi-asserted-by":"crossref","unstructured":"Bonneau, J., Herley, C., Van Oorschot, P.C., Stajano, F.: The quest to replace passwords: a framework for comparative evaluation of web authentication schemes. In: 2012 IEEE Symposium on Security and Privacy, pp. 553\u2013567. IEEE (2012)","DOI":"10.1109\/SP.2012.44"},{"key":"6_CR13","unstructured":"Chandel, A., Kumar, P., Yadav, D.K.: Phishing attack and its countermeasures. IEEE Electron. Device Lett 7, 569\u2013571 (1999)"},{"key":"6_CR14","unstructured":"Check Point Software Technologies Inc: Pc and mobile security software - zonealarm (2020). https:\/\/www.zonealarm.com\/"},{"key":"6_CR15","unstructured":"DataProt: A not-so-common cold: malware statistics in 2021 (2021). https:\/\/dataprot.net\/statistics\/malware-statistics\/"},{"key":"6_CR16","doi-asserted-by":"crossref","unstructured":"De Cristofaro, E., Du, H., Freudiger, J., Norcie, G.: A comparative usability study of two-factor authentication. arXiv preprint arXiv:1309.5344 (2013)","DOI":"10.14722\/usec.2014.23025"},{"key":"6_CR17","unstructured":"Duo: Duo two factor authentication and endpoint security (2020). https:\/\/duo.com"},{"key":"6_CR18","unstructured":"Facebook: Facebook (2020). https:\/\/www.facebook.com\/"},{"key":"6_CR19","unstructured":"Google: Google accounts (2020). https:\/\/accounts.google.com"},{"key":"6_CR20","doi-asserted-by":"crossref","unstructured":"Grimes, R.: The many ways to hack 2fa. Netw. Secur. 2019(9), 8\u201313 (2019)","DOI":"10.1016\/S1353-4858(19)30107-2"},{"key":"6_CR21","unstructured":"Karia, M.A.R., Patankar, A., Tawde, M.P.: SMS-based one time password vulnerabilities and safeguarding OTP over network. Int. J. Eng. Res. Technol. (IJERT) 3(5), 1339\u20131343 (2014)"},{"key":"6_CR22","doi-asserted-by":"crossref","unstructured":"Kuo, W.C., Lee, Y.C.: Attack and improvement on the one-time password authentication protocol against theft attacks. In: 2007 International Conference on Machine Learning and Cybernetics, vol. 4, pp. 1918\u20131922. IEEE (2007)","DOI":"10.1109\/ICMLC.2007.4370461"},{"key":"6_CR23","unstructured":"Logmeln Inc.: Lastpass - password manager & vault app (2020). https:\/\/www.lastpass.com\/"},{"key":"6_CR24","unstructured":"MalwareBytes: Malwarebytes cybersecurity for home and business (2020). https:\/\/www.malwarebytes.com\/"},{"key":"6_CR25","unstructured":"McAfee: Mcafee total protection (2020). https:\/\/www.mcafee.com\/en-us\/antivirus\/free.html"},{"key":"6_CR26","doi-asserted-by":"crossref","unstructured":"Molloy, I., Li, N.: Attack on the gridcode one-time password. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, pp. 306\u2013315 (2011)","DOI":"10.1145\/1966913.1966953"},{"key":"6_CR27","doi-asserted-by":"crossref","unstructured":"M\u2019Raihi, D., Bellare, M., Hoornaert, F., Naccache, D., Ranen, O.: Hotp: an hmac-based one-time password algorithm. The Internet Society, Network Working Group. RFC4226 (2005)","DOI":"10.17487\/rfc4226"},{"key":"6_CR28","doi-asserted-by":"crossref","unstructured":"M\u2019Raihi, D., Machani, S., Pei, M., Rydell, J.: Totp: time-based one-time password algorithm. Internet Request for Comments (2011)","DOI":"10.17487\/rfc6238"},{"key":"6_CR29","unstructured":"PhantomJS Contributors: Phantomjs- scriptable headless browser (2010\u20132018). https:\/\/phantomjs.org"},{"key":"6_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"324","DOI":"10.1007\/978-3-642-12368-9_26","volume-title":"Information Security Theory and Practices. Security and Privacy of Pervasive Systems and Smart Devices","author":"H Raddum","year":"2010","unstructured":"Raddum, H., Nest\u00e5s, L.H., Hole, K.J.: Security analysis of mobile phones used as OTP generators. In: Samarati, P., Tunstall, M., Posegga, J., Markantonakis, K., Sauveron, D. (eds.) WISTP 2010. LNCS, vol. 6033, pp. 324\u2013331. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-12368-9_26"},{"key":"6_CR31","unstructured":"RSA Security LLC.: RSA securid hardware tokens (2020). https:\/\/www.rsa.com\/en-us\/products\/rsa-securid-suite\/rsa-securid-access\/securid-hardware-tokens\/rsa-securid-hardware-tokens"},{"key":"6_CR32","unstructured":"Separd, D.: First-ever national study: millions of people rely on library computers for employment, health, and education (2020). https:\/\/www.gatesfoundation.org\/media-center\/press-releases\/2010\/03\/millions-of-people-rely-on-library-computers-for-employment-health-and-education"},{"key":"6_CR33","doi-asserted-by":"crossref","unstructured":"Siadati, H., Nguyen, T., Gupta, P., Jakobsson, M., Memon, N.: Mind your SMSes: mitigating social engineering in second factor authentication. Comput. Secur. 65, 14\u201328 (2017)","DOI":"10.1016\/j.cose.2016.09.009"},{"key":"6_CR34","unstructured":"Smith, N.: Hotp vs totp, whats the difference? (2018). https:\/\/www.microcosm.com\/blog\/hotp-totp-what-is-the-difference"},{"key":"6_CR35","unstructured":"Software Freedom Conservancy- Selenium Project: Selenium webdriver (2020). https:\/\/www.selenium.dev\/projects\/"},{"key":"6_CR36","unstructured":"Sophos Ltd: Sophos home - cybersecurity made simple (2020). https:\/\/home.sophos.com\/en-us.aspx"},{"key":"6_CR37","unstructured":"StatCounter: Operating system market share worldwide- february 2020 (2020). https:\/\/gs.statcounter.com\/os-market-share"},{"key":"6_CR38","unstructured":"TechJury.net: What is a keylogger? [everything you need to know] (2021). https:\/\/techjury.net\/blog\/what-is-a-keylogger\/"},{"key":"6_CR39","unstructured":"ThreatPost: 500 malicious chrome extensions impact millions of users (2020). https:\/\/threatpost.com\/500-malicious-chrome-extensions-millions\/152918\/"},{"key":"6_CR40","unstructured":"Twilio Inc.: Authy- two factor authentication (2fa) app & guides (2020). https:\/\/authy.com\/"},{"key":"6_CR41","unstructured":"Twitter Inc: Explore twitter (2020). https:\/\/twitter.com\/explore"},{"key":"6_CR42","unstructured":"VirusTotal: Virustotal (2020). https:\/\/www.virustotal.com\/gui\/home\/upload"},{"key":"6_CR43","doi-asserted-by":"crossref","unstructured":"Weir, C.S., Douglas, G., Carruthers, M., Jack, M.: User perceptions of security, convenience and usability for ebanking authentication tokens. Comput. Secur. 28(1\u20132), 47\u201362 (2009)","DOI":"10.1016\/j.cose.2008.09.008"},{"key":"6_CR44","doi-asserted-by":"crossref","unstructured":"Weir, C.S., Douglas, G., Richardson, T., Jack, M.: Usable security: user preferences for authentication methods in ebanking and the effects of experience. Interact. Comput. 22(3), 153\u2013164 (2010)","DOI":"10.1016\/j.intcom.2009.10.001"},{"key":"6_CR45","doi-asserted-by":"crossref","unstructured":"Yoo, C., Kang, B.T., Kim, H.K.: Case study of the vulnerability of OTP implemented in internet banking systems of South Korea. Multimedia Tools Appl. 74(10), 3289\u20133303 (2015)","DOI":"10.1007\/s11042-014-1888-3"},{"key":"6_CR46","unstructured":"Ziff Davis, LLC. PCMAG Digital Group: Windows computers were targets of 83% of all malware attacks in q1 2020 (2020). https:\/\/www.pcmag.com\/news\/windows-computers-account-for-83-of-all-malware-attacks-in-q1-2020"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-86890-1_6","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,9,17]],"date-time":"2021-09-17T00:59:12Z","timestamp":1631840352000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-86890-1_6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"ISBN":["9783030868895","9783030868901"],"references-count":46,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-86890-1_6","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2021]]},"assertion":[{"value":"17 September 2021","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information and Communications Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Chongqing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2021","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 September 2021","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 September 2021","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icics2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.icics.cn\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"182","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"49","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"27% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}