A Deep Dive Into Credential Gathering Attack
Restricted (Penn State Only)
- Author:
- Patel, Jiya
- Area of Honors:
- Information Sciences and Technology
- Degree:
- Bachelor of Science
- Document Type:
- Thesis
- Thesis Supervisors:
- Peng Liu, Thesis Supervisor
Edward J Glantz, Thesis Honors Advisor - Keywords:
- credential theft
credential gathering attacks
FIDO2
WebAuthn
browser attestation
Shamir Secret Sharing
account recovery
zero-knowledge proofs
Direct Anonymous Attestation
malware
LSASS
pass-the-hash
Kerberos - Abstract:
- Credentials are fundamental to digital identity. They are the means by which users prove who they are and gain access to services, portals, and online platforms. Identity and Access Management (IAM) encompasses the technologies and policies governing the identification, authentication, and authorization of users across computer networks. While passwords and PINs are the most familiar form of credentials, many others exist in modern systems such as password hashes, Kerberos tickets, payment card data, Windows NT hashes, OAuth tokens, and cryptographic certificates, among others. This thesis examines how credentials are stolen, often without any user interaction, how malware lo cates and extracts them from memory, disk, and network traffic, and how attackers leverage compromised credentials once obtained. Because credentials serve as the entry point for a wide range of cyberattacks, understanding why current systems make credential theft relatively straightforward is essential to designing more robust defenses. The second chapter surveys existing protection mechanisms, revealing critical gaps in how credential security is currently approached. A key observation motivating this work is that credential theft is not a monolithic problem, that is, different credential types are stored differently, stolen through different techniques, and exploited in different ways. Yet prevailing defense strategies tend to treat them uniformly, a significant misconception that leaves many attack surfaces inadequately protected. The final chapter proposes a new approach by extending the FIDO2 authentication standard. Rather than applying a one-size-fits-all defense, this work targets a specific credential scenario and develops a tailored security model that addresses shortcomings left unresolved by general-purpose defenses available today.
Accessible Version in Progress
We're generating an accessible version of this file to meet ADA Title II requirements. This process may take up to one hour. Please return later to access the accessible copy once it's ready.
You can still download the current version by clicking "OK".
What's happening:
An accessible PDF is being generated using Adobe with AI used to generate alternative text (alt text) for images in the PDF.