{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T00:05:02Z","timestamp":1780445102489,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,4,24]],"date-time":"2023-04-24T00:00:00Z","timestamp":1682294400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,4,24]]},"DOI":"10.1145\/3577923.3583634","type":"proceedings-article","created":{"date-parts":[[2023,4,20]],"date-time":"2023-04-20T10:57:59Z","timestamp":1681988279000},"page":"237-243","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["Risk-Based Authentication for OpenStack: A Fully Functional Implementation and Guiding Example"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5357-3599","authenticated-orcid":false,"given":"Vincent","family":"Unsel","sequence":"first","affiliation":[{"name":"H-BRS University of Applied Sciences, Sankt Augustin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7917-6065","authenticated-orcid":false,"given":"Stephan","family":"Wiefling","sequence":"additional","affiliation":[{"name":"Ruhr University Bochum, Bochum, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7360-8314","authenticated-orcid":false,"given":"Nils","family":"Gruschka","sequence":"additional","affiliation":[{"name":"University of Oslo, Oslo, Norway"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7863-0622","authenticated-orcid":false,"given":"Luigi","family":"Lo Iacono","sequence":"additional","affiliation":[{"name":"H-BRS University of Applied Sciences, Sankt Augustin, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,24]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Credential Stuffing: Attacks and Economies. [state of the internet] \/ security","year":"2019","unstructured":"Akamai. 2019. Credential Stuffing: Attacks and Economies. [state of the internet] \/ security , Vol. 5, Special Media Edition (April 2019). https:\/\/web.archive.org\/web\/20210824114851\/https:\/\/www.akamai.com\/us\/en\/multimedia\/documents\/state-of-the-internet\/soti-security-credential-stuffing-attacks-and-economies-report-2019.pdf"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991091"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-030--50399--4_16"},{"key":"e_1_3_2_1_4_1","unstructured":"Australian Cyber Security Centre. 2021. Australian Government Information Security Manual. Technical Report. https:\/\/web.archive.org\/web\/20210830131917\/https:\/\/www.cyber.gov.au\/sites\/default\/files\/2021-06\/01.%20ISM%20-%20Using%20the%20Australian%20Government%20Information%20Security%20Manual%20(June%202021).pdf"},{"key":"e_1_3_2_1_5_1","volume-title":"Executive Order on Improving the Nation's Cybersecurity","author":"Biden Joseph R.","year":"2021","unstructured":"Joseph R. Biden Jr. 2021. Executive Order on Improving the Nation's Cybersecurity. The White House (May 2021). https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SIN56466.2022.9970540"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3308558.3313481"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW.2019.00020"},{"key":"e_1_3_2_1_9_1","first-page":"21","article-title":"Who Are You? A Statistical Approach to Measuring User Authenticity","volume":"16","author":"Freeman David","year":"2016","unstructured":"David Freeman, Sakshi Jain, Markus D\u00fcrmuth, Battista Biggio, and Giorgio Giacinto. 2016. Who Are You? A Statistical Approach to Measuring User Authenticity.. In NDSS, Vol. 16. 21--24.","journal-title":"NDSS"},{"key":"e_1_3_2_1_10_1","volume-title":"Enigma","author":"Gaddam Ajit","year":"2019","unstructured":"Ajit Gaddam. 2019. Usage of Behavioral Biometric Technologies to Defend Against Bots. In Enigma 2019. USENIX Association."},{"key":"e_1_3_2_1_11_1","unstructured":"Simson L. Garfinkel. 2005. Design principles and patterns for computer systems that are simultaneously secure and usable."},{"key":"e_1_3_2_1_12_1","volume-title":"32nd USENIX Security Symposium (USENIX Security '23)","author":"Gavazzi Anthony","year":"2023","unstructured":"Anthony Gavazzi, Ryan Williams, Engin Kirda, Long Lu, Andre King, Andy Davis, and Tim Leek. 2023. A Study of Multi-Factor and Risk-Based Authentication Availability. In 32nd USENIX Security Symposium (USENIX Security '23). USENIX Association, Anaheim, CA, USA."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800--63--3"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.17487\/rfc1930"},{"key":"e_1_3_2_1_15_1","unstructured":"ISO 3166 Maintenance Agency. 2020. ISO 3166--1:2020(en) Codes for the representation of names of countries and their subdivisions - Part 1: Country code. ISO 3166--1. https:\/\/www.iso.org\/obp\/ui\/#iso:std:iso:3166:-1:ed-4:v1:en"},{"key":"e_1_3_2_1_16_1","unstructured":"Tom Le Bras. 2015. Online Overload -- It's Worse Than You Thought. https:\/\/web.archive.org\/web\/20150919202348\/https:\/\/blog.dashlane.com\/infographic-online-overload-its-worse-than-you-thought\/"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23386"},{"key":"e_1_3_2_1_18_1","volume-title":"Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022","author":"Markert Philipp","year":"2022","unstructured":"Philipp Markert, Theodor Schnitzler, Maximilian Golla, and Markus D\u00fcrmuth. 2022. \"As soon as ittextquoterights a risk, I want to require MFA\": How Administrators Configure Risk-based Authentication. In Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022). USENIX Association, Boston, MA, 483--501. https:\/\/www.usenix.org\/conference\/soups2022\/presentation\/markert"},{"key":"e_1_3_2_1_19_1","volume-title":"Enigma","author":"Milka Grzergor","year":"2018","unstructured":"Grzergor Milka. 2018. Anatomy of Account Takeover. In Enigma 2018. USENIX Association. https:\/\/www.usenix.org\/node\/208154"},{"key":"e_1_3_2_1_20_1","volume-title":"Brief: OpenStack Is Now Ready For Business. Forrester Report Brief (Sept.","author":"Miller Paul","year":"2015","unstructured":"Paul Miller and Lauren E Nelson. 2015. Brief: OpenStack Is Now Ready For Business. Forrester Report Brief (Sept. 2015)."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359172"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC4226"},{"key":"e_1_3_2_1_24_1","unstructured":"Lily Hay Newman. 2021. Facebook Will Force More At-Risk Accounts to Use Two-Factor. https:\/\/web.archive.org\/web\/20211212185008\/https:\/\/www.wired.com\/story\/facebook-protect-two-factor-authentication-requirement\/"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2751323.2751327"},{"key":"e_1_3_2_1_26_1","unstructured":"PyData Development Team. 2020. pandas documentation. https:\/\/pandas.pydata.org\/pandas-docs\/version\/1.1.5\/."},{"key":"e_1_3_2_1_27_1","unstructured":"Nils Quermann Marian Harbach and Markus D\u00fcrmuth. 2018. The State of User Authentication in the Wild. In Who are you?! Adventures in Authentication Workshop 2018 (WAY '18). https:\/\/wayworkshop.org\/2018\/papers\/way2018-quermann.pdf"},{"key":"e_1_3_2_1_28_1","volume-title":"Fifteenth Symposium on Usable Privacy and Security (SOUPS '19)","author":"Reese Ken","year":"2019","unstructured":"Ken Reese, Trevor Smith, Jonathan Dutson, Jonathan Armknecht, Jacob Cameron, and Kent Seamons. 2019. A Usability Study of Five Two-Factor Authentication Methods. In Fifteenth Symposium on Usable Privacy and Security (SOUPS '19). USENIX Association, 357--370. https:\/\/www.usenix.org\/conference\/soups2019\/presentation\/reese"},{"key":"e_1_3_2_1_29_1","volume-title":"Top Programming Languages","author":"Spectrum IEEE","year":"2022","unstructured":"IEEE Spectrum. 2022. Top Programming Languages 2022. https:\/\/spectrum.ieee.org\/top-programming-languages-2022"},{"key":"e_1_3_2_1_30_1","unstructured":"Costas Tsaousis. 2022. All Cybercrime IP Feeds. https:\/\/iplists.firehol.org\/."},{"key":"e_1_3_2_1_31_1","unstructured":"Twitter. 2022. Account Security - Twitter Transparency Center. https:\/\/web.archive.org\/web\/20220211182429\/https:\/\/transparency.twitter.com\/en\/reports\/account-security.html#2021-jan-jun"},{"key":"e_1_3_2_1_32_1","unstructured":"Stephan Wiefling. 2022. Basic Algorithm for Risk-Based Authentication. https:\/\/github.com\/das-group\/rba-algorithm"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427243"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-64331-0_19"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3546069"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-030--22312-0_10"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-030--58201--2_19"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW54576.2021.00040"}],"event":{"name":"CODASPY '23: Thirteenth ACM Conference on Data and Application Security and Privacy","location":"Charlotte NC USA","acronym":"CODASPY '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3577923.3583634","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3577923.3583634","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:08:41Z","timestamp":1750183721000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3577923.3583634"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,24]]},"references-count":37,"alternative-id":["10.1145\/3577923.3583634","10.1145\/3577923"],"URL":"https:\/\/doi.org\/10.1145\/3577923.3583634","relation":{},"subject":[],"published":{"date-parts":[[2023,4,24]]},"assertion":[{"value":"2023-04-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}