{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,17]],"date-time":"2026-04-17T16:13:50Z","timestamp":1776442430834,"version":"3.51.2"},"reference-count":15,"publisher":"Breda Publishing Press","issue":"2","license":[{"start":{"date-parts":[[2021,2,1]],"date-time":"2021-02-01T00:00:00Z","timestamp":1612137600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Network Security"],"published-print":{"date-parts":[[2021,2]]},"abstract":"<jats:p> At the heart of IT security is a simple concept \u2013 proving you are who you say you are. In this context, \u2018you\u2019 might be a human logging into a network or service, a device interacting with an application programming interface (API), one network talking to another or any number of other scenarios. And the proof could be a certificate, an SSH key, a token of some form or our old favourite \u2013 and inevitably the artefact we'll be talking most about here \u2013 the old, fragile and yet seemingly unkillable password. <\/jats:p><jats:p> At the heart of IT security is a simple concept \u2013 proving that you are who you say you are. But the ways we have of doing that, through credentials of some form, are flawed. <\/jats:p><jats:p> Credential abuse comes in many forms. The question we need to ask is, where does it sit in terms of an organisation's attack surface and security priorities? In the first of a two-part feature, Steve Mansfield-Devine surveys a number of industry experts to get their views on what forms of credential abuse are being encountered and the threat these pose to enterprises. <\/jats:p>","DOI":"10.1016\/s1353-4858(21)00018-0","type":"journal-article","created":{"date-parts":[[2021,2,23]],"date-time":"2021-02-23T22:05:11Z","timestamp":1614117911000},"page":"6-15","source":"Crossref","is-referenced-by-count":2,"title":["Who's that knocking at the door? The problem of credential abuse"],"prefix":"10.70985","volume":"2021","author":[{"given":"Steve","family":"Mansfield-Devine","sequence":"first","affiliation":[{"name":"Network Security"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"51855","reference":[{"key":"bib1","volume-title":"\u2018Privileged Access Threat Report 2019\u2019","year":"2019"},{"key":"bib2","volume-title":"\u2018Penetration testing of corporate information systems\u2019","year":"2020"},{"key":"bib3","unstructured":"Jon Brodkin   \u2018Hacker says he correctly guessed Trump's Twitter password \u2014 it was \u201cmaga2020!\u201d\u2019; \n22 Oct 2020: \nArs Technica>\nhttps:\/\/arstechnica.com\/tech-policy\/2020\/10\/hacker-says-he-correctly-guessed-trumps-twitter-password-it-was-maga2020\/ accessed February 2021"},{"key":"bib4","unstructured":"Brian Krebs   \u2018Security blueprints of many companies leaked in hack of Swedish firm Gunnebo\u2019; \n28 Oct 2020: \nKrebs On Security>\nhttps:\/\/krebsonsecurity.com\/2020\/10\/security-blueprints-of-many-companies-leaked-in-hack-of-swedish-firm-gunnebo\/ accessed February 2021"},{"key":"bib6","unstructured":"Catalin Cimpanu   \u2018Shopify discloses security incident caused by two rogue employees\u2019; \n23 Sep 2020: \nZDNet>\nwww.zdnet.com\/article\/shopify-discloses-security-incident-caused-by-two-rogue-employees\/ accessed February 2021"},{"key":"bib7","volume-title":"\u2018Cybersecurity threatscape: Q1 2020\u2019","year":"2020"},{"key":"bib8","volume-title":"\u2018Cybersecurity threatscape: Q2 2020\u2019","year":"2020"},{"key":"bib9","unstructured":"Nicole Lindsey   \u2018Toyota subsidiary loses $37 million due to BEC scam\u2019; \n20 Sep 2019: \nCPO Magazine>\nwww.cpomagazine.com\/cybersecurity\/toyota-subsidiary-loses-37-million-due-to-bec-scam\/ accessed February 2021"},{"key":"bib11","unstructured":"\u2018State of the Internet 2020\u2019. Akamai; \nwww.akamai.com\/uk\/en\/resources\/our-thinking\/state-of-the-Internet-report\/archives\/state-of-the-Internet-security-reports-2020.jsp accessed February 2021"},{"key":"bib12","unstructured":"\u2018Streaming services among the most targeted by credential stuffing attacks according to Akamai report\u2019. Akamai, via Cision; \nwww.prnewswire.com\/news-releases\/streaming-services-among-the-most-targeted-by-credential-stuffing-attacks-according-to-akamai-report-300825838.html 8 Apr 2019: accessed February 2021"},{"key":"bib13","unstructured":"Bradley Barth   \u2018Gaming industry has become popular target of credential stuffing attacks: study\u2019; \n13 Jun 2019: \nSC Media>\nwww.scmagazine.com\/home\/security-news\/gaming-industry-has-become-popular-target-of-credential-stuffing-attacks-study\/ accessed February 2021"},{"key":"bib15","unstructured":"David McNeely   \u2018Centrify Mid-Year Data Breach Report: Credential Abuse, a Top Threat of Cyber Attacks\u2019; \n5 Aug 2019: \nCentrify>\nwww.centrify.com\/blog\/centrify-data-breach-credential-abuse\/ accessed February 2021"},{"key":"bib16","unstructured":"\u2018Survey: Privileged Access Management in the Modern Threatscape\u2019. Centrify; \nwww.centrify.com\/resources\/centrify-privileged-access-management-in-the-modern-threatscape-2019\/ accessed February 2021"},{"key":"bib17","volume-title":"\u2018Most credential abuse attacks against the financial sector targeted APIs\u2019","year":"2020"},{"key":"bib18","unstructured":"Jim Brunner  \nPaul Roberts  \nPatrick Malone   \u2018How missed \u2018red flags\u2019 helped Nigerian fraud ring \u2018Scattered Canary\u2019 bilk Washington's unemployment system amid coronavirus chaos\u2019; \n24 May 2020: \nSeattle Times>\nwww.seattletimes.com\/seattle-news\/times-watchdog\/how-missed-red-flags-helped-nigerian-fraud-ring-scattered-canary-bilk-washingtons-unemployment-system-amid-coronavirus-chaos\/ accessed February 2021"}],"container-title":["Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1353485821000180?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1353485821000180?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/www.magonlinelibrary.com\/doi\/pdf\/10.1016\/S1353-4858%2821%2900018-0","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,3]],"date-time":"2024-12-03T22:21:05Z","timestamp":1733264465000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.magonlinelibrary.com\/doi\/10.1016\/S1353-4858%2821%2900018-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,2]]},"references-count":15,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2021,2]]}},"alternative-id":["10.1016\/S1353-4858(21)00018-0"],"URL":"https:\/\/doi.org\/10.1016\/s1353-4858(21)00018-0","relation":{},"ISSN":["1353-4858","1872-9371"],"issn-type":[{"value":"1353-4858","type":"print"},{"value":"1872-9371","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,2]]}}}