<oai_dc:dc xmlns:oai_dc="http://www.openarchives.org/OAI/2.0/oai_dc/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/oai_dc/ http://www.openarchives.org/OAI/2.0/oai_dc.xsd"><dc:title>A Deep Dive Into Credential Gathering Attack </dc:title><dc:creator>Patel, Jiya </dc:creator><dc:subject>credential theft</dc:subject><dc:subject>credential gathering attacks</dc:subject><dc:subject>FIDO2</dc:subject><dc:subject>WebAuthn</dc:subject><dc:subject>browser attestation</dc:subject><dc:subject>Shamir Secret Sharing</dc:subject><dc:subject>account recovery</dc:subject><dc:subject>zero-knowledge proofs</dc:subject><dc:subject>Direct Anonymous Attestation</dc:subject><dc:subject>malware</dc:subject><dc:subject>LSASS</dc:subject><dc:subject>pass-the-hash</dc:subject><dc:subject>Kerberos</dc:subject><dc:coverage>Information Sciences and Technology</dc:coverage><dc:relation>B S</dc:relation><dc:description>Credentials are fundamental to digital identity. They are the means by which users prove who they
are and gain access to services, portals, and online platforms. Identity and Access Management (IAM)
encompasses the technologies and policies governing the identification, authentication, and authorization of users across computer networks. While passwords and PINs are the most familiar form of credentials, many others exist in modern systems such as password hashes, Kerberos tickets, payment card data, Windows NT hashes, OAuth tokens, and cryptographic certificates, among others.

This thesis examines how credentials are stolen, often without any user interaction, how malware lo
cates and extracts them from memory, disk, and network traffic, and how attackers leverage compromised credentials once obtained. Because credentials serve as the entry point for a wide range of cyberattacks, understanding why current systems make credential theft relatively straightforward is essential to designing more robust defenses.

The second chapter surveys existing protection mechanisms, revealing critical gaps in how credential
security is currently approached. A key observation motivating this work is that credential theft is not
a monolithic problem, that is, different credential types are stored differently, stolen through different
techniques, and exploited in different ways. Yet prevailing defense strategies tend to treat them uniformly, a significant misconception that leaves many attack surfaces inadequately protected.

The final chapter proposes a new approach by extending the FIDO2 authentication standard. Rather
than applying a one-size-fits-all defense, this work targets a specific credential scenario and develops a tailored security model that addresses shortcomings left unresolved by general-purpose defenses available today.</dc:description><dc:contributor>Peng Liu, Thesis Supervisor</dc:contributor><dc:contributor>Edward J Glantz, Thesis Honors Advisor</dc:contributor><dc:rights>restricted_to_institution</dc:rights><dc:date>2026-04-01T00:48:52Z</dc:date><dc:identifier>https://honors.libraries.psu.edu/catalog/10014jfp5939</dc:identifier></oai_dc:dc>