Social Engineering Resistant 2FA
This addresses security vulnerabilities for users and organizations, but appears incremental as it modifies existing 2FA methods.
The paper tackles the problem of attackers using social engineering to bypass second factor authentication (2FA) by introducing device-aware 2FA to replace traditional security codes, though no concrete results or numbers are provided.
Attackers increasingly, and with high success rates, use social engineering techniques to circumvent second factor authentication (2FA) technologies, compromise user accounts and sidestep fraud detection technologies. We introduce a social engineering resistant approach that we term device-aware 2FA, to replace the use of traditional security codes.