Credentials Stuffing Attack Prevention Using Machine Learning

Md Mahmuduzzaman Kamol, Md Shamim Siddiky, Fahim Anwar, Al-Monaem Khan, Abdus Salam · 2024

Millions of compromised databases are traded online daily, allowing hackers to exploit users’ accounts and posing a significant threat to online security by jeopardizing individuals’ sensitive information. There is an urgent need for enhanced cybersecurity measures and increased public awareness to mitigate these risks. This study highlights the significant concern of account cracking stuffing attacks, a prevalent cybersecurity threat that endangers online systems. Our research implemented machine learning methodologies on web access logs to develop a proactive approach for detecting and preventing unauthorized access attempts. We propose a novel solution that utilizes machine learning on web access logs to enhance account security dynamically and adaptively. By effectively using the DBSCAN clustering algorithm to detect discrete user behavior clusters, we categorize user activities into normal and potentially malicious actors, providing critical insights for preventing credential stuffing. The implications of our findings are substantial for cybersecurity, presenting a proactive and effective measure to enhance online account security. Organizations can secure user data and reduce unauthorized access risks by detecting and thwarting account cracking attempts in real-time. This research adds value to cybersecurity by introducing a novel machine learning-based method for scrutinizing web access, providing a tool to stay ahead of cyber threats and fortify user accounts.

Read the paper · More papers on PaperTik