{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,2]],"date-time":"2025-11-02T20:11:57Z","timestamp":1762114317991,"version":"build-2065373602"},"reference-count":10,"publisher":"Breda Publishing Press","issue":"3","license":[{"start":{"date-parts":[[2021,3,1]],"date-time":"2021-03-01T00:00:00Z","timestamp":1614556800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Network Security"],"published-print":{"date-parts":[[2021,3]]},"abstract":"<jats:p> Credential abuse is a major issue facing organisations of all sizes. It affects not only simple login processes but also solutions and technologies such as application programming interfaces (APIs), the deployment of Internet of Things (IoT) devices and machine-to-machine authentication. Cyber criminals and nation-state attackers alike have automated the process of credential abuse while also refining highly targeted attacks. And the problem is getting worse. <\/jats:p><jats:p> Credential abuse is a major issue facing organisations of all sizes. Cyber criminals and nation-state attackers alike have automated the process while also refining highly targeted attacks. <\/jats:p><jats:p> The problem is getting worse and credential abuse presents itself in many forms. And there are equally as many solutions touted by vendors, all of which have their own challenges and weaknesses. However, there are successful solutions available and tackling the issue just takes a proper awareness of the problem and applying the appropriate technology and training, writes Steve Mansfield-Devine. <\/jats:p>","DOI":"10.1016\/s1353-4858(21)00030-1","type":"journal-article","created":{"date-parts":[[2021,3,23]],"date-time":"2021-03-23T12:33:40Z","timestamp":1616502820000},"page":"11-19","source":"Crossref","is-referenced-by-count":2,"title":["Locking the door: tackling credential abuse"],"prefix":"10.70985","volume":"2021","author":[{"given":"Steve","family":"Mansfield-Devine","sequence":"first","affiliation":[{"name":"Network Security"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"51855","reference":[{"key":"bib1","doi-asserted-by":"crossref","unstructured":"Steve Mansfield-Devine   \u2018Who\u2019s that knocking at the door? The problem of credential abuse\u2019; \nFeb 2021: \nNetwork Security>\nAccessed Feb 2021.","DOI":"10.1016\/S1353-4858(21)00018-0"},{"key":"bib2","unstructured":"Alina Selyukh  \nCamila Domonoske   \u2018Apple, the FBI and iPhone encryption: a look at what\u2019s at stake\u2019; \n17 Feb 2016: \nNPR>\nwww.npr.org\/sections\/thetwo-way\/2016\/02\/17\/467096705\/apple-the-fbi-and-iphone-encryption-a-look-at-whats-at-stake?t=1614163847013 accessed February 2021"},{"key":"bib3","unstructured":"\u2018FBI \u2013 Apple encryption dispute\u2019. Wikipedia; \nhttps:\/\/en.wikipedia.org\/wiki\/FBI%E2%80%93Apple_encryption_dispute accessed February 2021"},{"key":"bib4","unstructured":"Zeljka Zorz   \u2018Reddit suffers data breach despite using SMS-based 2FA\u2019; \n2 Aug 2018: \nHelpNet Security>\nwww.helpnetsecurity.com\/2018\/08\/02\/reddit-breach\/ accessed February 2021"},{"volume-title":"\u2018Evilginx2 \u2013 standalone MITM attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication\u2019","year":"2018","key":"bib5"},{"key":"bib6","unstructured":"\u2018ISO\/IEC 27000:2018\u2019. ISO; \nwww.iso.org\/standard\/73906.html accessed February 2021"},{"key":"bib7","unstructured":"\u2018The Cyber Kill Chain\u2019. Lockheed Martin; \nwww.lockheedmartin.com\/en-us\/capabilities\/cyber\/cyber-kill-chain.html accessed February 2021"},{"key":"bibB1","unstructured":"Georgia Hitch  \nAndrew Probyn   \u2018China believed to be behind major cyber attack on Australian governments and businesses\u2019; \n19 Jun 2020: \nABC News>\nwww.abc.net.au\/news\/2020-06-19\/foreign-cyber-hack-targets-australian-government-and-business\/12372470 accessed February 2021"},{"volume-title":"\u2018Top 10 Security Projects for 2019\u2019","year":"2019","key":"bibB2"},{"key":"bibB3","unstructured":"Andras Cser  \nSean Ryan  \nMerritt Maxim  \nBenjamin Corey  \nPeggy Dostie   \u2018Making The Business Case For Identity And Access Management\u2019; \n4 Dec 2020: \nForrester>\nwww.forrester.com\/report\/Making+The+Business+Case+For+Identity+And+Access+Management\/-\/E-RES80481 accessed February 2021"}],"container-title":["Network Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1353485821000301?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S1353485821000301?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/www.magonlinelibrary.com\/doi\/pdf\/10.1016\/S1353-4858%2821%2900030-1","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,3]],"date-time":"2024-12-03T22:21:12Z","timestamp":1733264472000},"score":1,"resource":{"primary":{"URL":"http:\/\/www.magonlinelibrary.com\/doi\/10.1016\/S1353-4858%2821%2900030-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,3]]},"references-count":10,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2021,3]]}},"alternative-id":["10.1016\/S1353-4858(21)00030-1"],"URL":"https:\/\/doi.org\/10.1016\/s1353-4858(21)00030-1","relation":{},"ISSN":["1353-4858","1872-9371"],"issn-type":[{"type":"print","value":"1353-4858"},{"type":"electronic","value":"1872-9371"}],"subject":[],"published":{"date-parts":[[2021,3]]}}}