Towards an Improved Taxonomy of Attacks related to Digital Identities and Identity Management Systems
Daniela P\"ohn, Wolfgang Hommel

TL;DR
This paper introduces an improved taxonomy, TaxIdMA, for classifying attacks on identity management systems, enhancing security understanding and sharing across diverse scenarios like IoT and self-sovereign identities.
Contribution
The paper presents a systematic taxonomy, TaxIdMA, for classifying identity-related attacks, and introduces a description language for threat intelligence sharing, validated through expert input and statistical analysis.
Findings
TaxIdMA effectively classifies identity attacks across scenarios.
The taxonomy improves threat understanding and communication.
Enhanced security measures for identity management systems.
Abstract
Digital transformation with the adoption of cloud technologies, outsourcing, and working-from-home possibilities permits flexibility for organizations and persons. At the same time, it makes it more difficult to secure the IT infrastructure as the IT team needs to keep track of who is accessing what data from where and when on which device. With these changes, identity management as a key element of security becomes more important. Identity management relates to the technologies and policies for the identification, authentication, and authorization of users (humans, devices) in computer networks. Due to the diversity of identity management (i.e., models, protocols, and implementations), different requirements, problems, and attack vectors need to be taken into account. In order to secure identity management systems with their identities, a systematic approach is required. In this…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
