{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,14]],"date-time":"2026-01-14T22:29:54Z","timestamp":1768429794655,"version":"3.49.0"},"publisher-location":"Cham","reference-count":43,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031641701","type":"print"},{"value":"9783031641718","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-64171-8_15","type":"book-chapter","created":{"date-parts":[[2024,7,10]],"date-time":"2024-07-10T11:02:33Z","timestamp":1720609353000},"page":"283-306","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Knocking on\u00a0Admin\u2019s Door: Protecting Critical Web Applications with\u00a0Deception"],"prefix":"10.1007","author":[{"given":"Billy","family":"Tsouvalas","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nick","family":"Nikiforakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,7,9]]},"reference":[{"key":"15_CR1","doi-asserted-by":"crossref","unstructured":"Van Acker, S., Hausknecht, D., Sabelfeld, A.: Measuring login webpage security. In: Proceedings of the Symposium on Applied Computing (2017)","DOI":"10.1145\/3019612.3019798"},{"key":"15_CR2","doi-asserted-by":"crossref","unstructured":"Das, A., Bonneau, J., Caesar, M., Borisov, N., Wang, X.F.: The tangled web of password reuse. In: NDSS, vol. 14, pp. 23\u201326 (2014)","DOI":"10.14722\/ndss.2014.23357"},{"key":"15_CR3","doi-asserted-by":"crossref","unstructured":"Florencio, D., Herley, C.: A large-scale study of web password habits. In: Proceedings of the 16th International Conference on World Wide Web (2007)","DOI":"10.1145\/1242572.1242661"},{"key":"15_CR4","doi-asserted-by":"crossref","unstructured":"Bonneau, J., Herley, C., Van Oorschot, P.C., Stajano, F.: The quest to replace passwords: a framework for comparative evaluation of web authentication schemes. In: 2012 IEEE Symposium on Security and Privacy (2012)","DOI":"10.1109\/SP.2012.44"},{"key":"15_CR5","unstructured":"Reynolds, J., et al.: Empirical measurement of systemic $$\\{$$2FA$$\\}$$ usability. In: 29th USENIX Security Symposium (2020)"},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Petsas, T., Tsirantonakis, G., Athanasopoulos, E., Ioannidis, S.: Two-factor authentication: is the world ready? Quantifying 2FA adoption. In: 8th European Workshop on System Security (2015)","DOI":"10.1145\/2751323.2751327"},{"key":"15_CR7","unstructured":"Lin, X., Ilia, P., Solanki, S., Polakis, J.: Phish in sheep\u2019s clothing: exploring the authentication pitfalls of browser fingerprinting. In: 31st USENIX Security Symposium (2022)"},{"key":"15_CR8","unstructured":"Pearman, S., Zhang, S.A., Bauer, L., Christin, N., Cranor, L.F.: Why people (don\u2019t) use password managers effectively. In: 15th Symposium on Usable Privacy and Security (SOUPS 2019) (2019)"},{"key":"15_CR9","unstructured":"F5 labs 2023 identity threat report: The unpatchables. https:\/\/www.f5.com\/labs\/articles\/threat-intelligence\/2023-identity-threat-report-the-unpatchables"},{"key":"15_CR10","unstructured":"Troy Hunt - Have I Been pwned? (2018). https:\/\/haveibeenpwned.com\/"},{"key":"15_CR11","doi-asserted-by":"crossref","unstructured":"Li, X., Azad, B.A., Rahmati, A., Nikiforakis, N.: Good bot, bad bot: characterizing automated browsing activity. In: 2021 IEEE Symposium on Security and Privacy (2021)","DOI":"10.1109\/SP40001.2021.00079"},{"key":"15_CR12","unstructured":"Ilascu, I.: Bleeping Computer: Uber Fined for Covering Up 2016 Data Breach (2018). https:\/\/www.bleepingcomputer.com\/news\/security\/uber-fined-for-covering-up-2016-data-breach\/"},{"key":"15_CR13","unstructured":"Degraaf, R., Aycock, J., Jacobson, M.: Improved port knocking with strong authentication. In: 21st Annual Computer Security Applications Conference (ACSAC\u201905)"},{"key":"15_CR14","unstructured":"Pochat, V.L., Van Goethem, T., Tajalizadehkhoob, S., Korczy\u0144ski, M., Joosen, W.: Tranco: a research-oriented top sites ranking hardened against manipulation. arXiv preprint arXiv:1806.01156 (2018)"},{"key":"15_CR15","unstructured":"Cortesi, A., Hils, M., Kriechbaumer, T.: Mitmproxy: a free and open source interactive HTTPS proxy (2010). contributors"},{"key":"15_CR16","unstructured":"Let\u2019sEncrypt (2023). https:\/\/letsencrypt.org\/"},{"key":"15_CR17","unstructured":"Certificate Transparency (2023). https:\/\/certificate.transparency.dev\/"},{"key":"15_CR18","unstructured":"Kondracki, B., So, J., Nikiforakis, N.: Uninvited guests: Analyzing the identity and behavior of certificate transparency bots. In: 31st USENIX Security Symposium (2022)"},{"key":"15_CR19","doi-asserted-by":"crossref","unstructured":"Kondracki, B., Azad, B.A., Starov, O., Nikiforakis, N.: Catching transparent phish: analyzing and detecting mitm phishing toolkits. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security (2021)","DOI":"10.1145\/3460120.3484765"},{"key":"15_CR20","doi-asserted-by":"crossref","unstructured":"Stoll, C.: Stalking the wily hacker. Commun. ACM (1988)","DOI":"10.1145\/42411.42412"},{"key":"15_CR21","unstructured":"Provos, N., et al.: A virtual honeypot framework. In: USENIX Security Symposium (2004)"},{"key":"15_CR22","unstructured":"The Honeynet Project (2023). https:\/\/www.honeynet.org\/"},{"key":"15_CR23","doi-asserted-by":"crossref","unstructured":"Bercovitch, M., Renford, M., Hasson, L., Shabtai, A., Rokach, L., Elovici, Y.: HoneyGen: an automated honeytokens generator. In: Proceedings of 2011 IEEE International Conference on Intelligence and Security Informatics (2011)","DOI":"10.1109\/ISI.2011.5984063"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"Juels, A., Rivest, R.L.: Honeywords: making password-cracking detectable. In: Proceedings of the 2013 ACM SIGSAC Conference on Computer & Communications Security (2013)","DOI":"10.1145\/2508859.2516671"},{"key":"15_CR25","series-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/978-3-642-05284-2_4","volume-title":"Security and Privacy in Communication Networks","author":"BM Bowen","year":"2009","unstructured":"Bowen, B.M., Hershkop, S., Keromytis, A.D., Stolfo, S.J.: Baiting inside attackers using decoy documents. In: Chen, Y., Dimitriou, T.D., Zhou, J. (eds.) SecureComm 2009. LNICST, vol. 19, pp. 51\u201370. Springer, Heidelberg (2009). https:\/\/doi.org\/10.1007\/978-3-642-05284-2_4"},{"key":"15_CR26","doi-asserted-by":"crossref","unstructured":"Voris, J., Jermyn, J., Boggs, N., Stolfo, S.: Fox in the trap: thwarting masqueraders via automated decoy document deployment. In: Proceedings of the Eighth European Workshop on System Security (2015)","DOI":"10.1145\/2751323.2751326"},{"key":"15_CR27","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1007\/978-3-642-22424-9_3","volume-title":"Detection of Intrusions and Malware, and Vulnerability Assessment","author":"M Ben Salem","year":"2011","unstructured":"Ben Salem, M., Stolfo, S.J.: Decoy document deployment for effective masquerade attack detection. In: Holz, T., Bos, H. (eds.) DIMVA 2011. LNCS, vol. 6739, pp. 35\u201354. Springer, Heidelberg (2011). https:\/\/doi.org\/10.1007\/978-3-642-22424-9_3"},{"key":"15_CR28","unstructured":"Nikiforakis, N., Balduzzi, M., Van Acker, S., Joosen, W., Balzarotti, D.: Exposing the lack of privacy in file hosting services. In: 4th USENIX Workshop on Large-Scale Exploits and Emergent Threats (LEET 2011) (2011)"},{"key":"15_CR29","doi-asserted-by":"crossref","unstructured":"Vasilomanolakis, E., Srinivasa, S., Cordero, C.G., M\u00fchlh\u00e4user, M. Multi-stage attack detection and signature generation with ICS honeypots. In: NOMS 2016 IEEE\/IFIP Network Operations and Management Symposium (2016)","DOI":"10.1109\/NOMS.2016.7502992"},{"key":"15_CR30","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"118","DOI":"10.1007\/978-3-642-15512-3_7","volume-title":"Recent Advances in Intrusion Detection","author":"BM Bowen","year":"2010","unstructured":"Bowen, B.M., Prabhu, P., Kemerlis, V.P., Sidiroglou, S., Keromytis, A.D., Stolfo, S.J.: BotSwindler: tamper resistant injection of believable decoys in VM-based hosts for crimeware detection. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol. 6307, pp. 118\u2013137. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15512-3_7"},{"key":"15_CR31","doi-asserted-by":"crossref","unstructured":"Park, Y., Stolfo, S.J.: Software decoys for insider threat. In: Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security (2012)","DOI":"10.1145\/2414456.2414511"},{"key":"15_CR32","doi-asserted-by":"crossref","unstructured":"Araujo, F., Hamlen, K.W., Biedermann, S., Katzenbeisser, S.: From patches to honey-patches: lightweight attacker misdirection, deception, and disinformation. In: 2014 ACM SIGSAC conference on Computer and Communications Security (2014)","DOI":"10.1145\/2660267.2660329"},{"key":"15_CR33","doi-asserted-by":"crossref","unstructured":"Sahin, M., Hebert, C., De Oliveira, A.S.: Lessons learned from sundew: a self defense environment for web applications. In: Proceedings of the 2020 Measurements, Attacks, and Defenses for the Web (MADWeb) Workshop in the Network and Distributed System Security Symposium (NDSS) (2020)","DOI":"10.14722\/madweb.2020.23005"},{"key":"15_CR34","doi-asserted-by":"publisher","unstructured":"Sahin, M., Hebert, C., Cabrera Lozoya, R.: An approach to generate realistic HTTP parameters for application layer deception. In: Ateniese, G., Venturi, D. (eds.) Applied Cryptography and Network Security. ACNS 2022. LNCS, vol. 13269, pp. 337\u2013355. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-09234-3_17","DOI":"10.1007\/978-3-031-09234-3_17"},{"key":"15_CR35","doi-asserted-by":"crossref","unstructured":"Bowen, B.M., Kemerlis, V.P., Prabhu, P., Keromytis, A.D., Stolfo, S.J.: Automating the injection of believable decoys to detect snooping. In: Proceedings of the 3rd ACM Conference on Wireless Network Security (2010)","DOI":"10.1145\/1741866.1741880"},{"key":"15_CR36","doi-asserted-by":"crossref","unstructured":"Reti, D., Fraunholz, D., Elzer, K., Schneider, D., Schotten, H.D.: Evaluating deception and moving target defense with network attack simulation. In: Proceedings of the 9th ACM Workshop on Moving Target Defense (2022)","DOI":"10.1145\/3560828.3564006"},{"key":"15_CR37","doi-asserted-by":"crossref","unstructured":"Fraunholz, D., Reti, D., Duque Anton, S., Schotten, H.D.: Cloxy: a context-aware deception-as-a-service reverse proxy for web services. In: Proceedings of the 5th ACM workshop on Moving Target Defense (2018)","DOI":"10.1145\/3268966.3268973"},{"key":"15_CR38","doi-asserted-by":"crossref","unstructured":"Fraunholz, D., Schotten, H.D.: Defending web servers with feints, distraction and obfuscation. In: 2018 International Conference on Computing, Networking and Communications (ICNC) (2018)","DOI":"10.1109\/ICCNC.2018.8390365"},{"key":"15_CR39","unstructured":"Anagnostakis, K.G., Sidiroglou, S., Akritidis, P., Xinidis, K., Markatos, E., Keromytis, A.D.: Detecting targeted attacks using shadow honeypots. In: 14th USENIX Security Symposium (2005)"},{"key":"15_CR40","doi-asserted-by":"crossref","unstructured":"Urias, V.E., Stout, W.M., Lin, H.W.: Gathering threat intelligence through computer network deception. In: 2016 IEEE Symposium on Technologies for Homeland Security (HST) (2016)","DOI":"10.1109\/THS.2016.7568916"},{"key":"15_CR41","doi-asserted-by":"crossref","unstructured":"Barron, T., So, J., Nikiforakis, N.: Click this, not that: extending web authentication with deception. In: Proceedings of the 2021 ACM Asia Conference on Computer and Communications Security (2021)","DOI":"10.1145\/3433210.3453088"},{"key":"15_CR42","unstructured":"Ferguson-Walter, K.J., Major, M.M., Johnson, C.K., Muhleman, D.H.: Examining the efficacy of decoy-based and psychological cyber deception. In: USENIX Security Symposium (2021)"},{"key":"15_CR43","unstructured":"W3Techs. Usage statistics and market share of WordPress (2023). https:\/\/w3techs.com\/technologies\/details\/cm-wordpress"}],"container-title":["Lecture Notes in Computer Science","Detection of Intrusions and Malware, and Vulnerability Assessment"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-64171-8_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,10]],"date-time":"2024-07-10T11:12:21Z","timestamp":1720609941000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-64171-8_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031641701","9783031641718"],"references-count":43,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-64171-8_15","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"9 July 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DIMVA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Lausanne","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Switzerland","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 July 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 July 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dimva2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dimva.org\/dimva2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}