ANALYSIS OF CREDENTIAL STUFFING & PASSWORD SPRAYING ATTACK MODELS AND A DEFENSE-IN-DEPTH STRATEGY FOR HIGHER EDUCATION MANAGEMENT SYSTEMS
In the digital transformation of higher education, academic management portals and Learning Management Systems (LMS) have become primary targets for automated cyberattacks. Although server-side password storage hashing algorithms such as Bcrypt or Scrypt have proven effective against database offline cracking, they remain largely ineffective against password enumeration attacks executed through legitimate authentication flows, specifically Credential Stuffing and Password Spraying. This paper presents an in-depth analysis of the theoretical models of Credential Stuffing and Password Spraying, highlighting system vulnerabilities and specific security risks inherent to the higher education environment. On this basis, the study proposes a 4-layer Defense-in-Depth Architecture consisting of independent yet complementary control layers, integrating security standards from OWASP and NIST. The research findings contribute a solid theoretical foundation to assist educational institutions in optimizing their information security infrastructure without compromising the digital user experience.
Authors
- Bùi Thị Thuý Quỳnh
- Nguyen Thi Hong Mai
- Nguyen Manh Hung
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-08-27
- DOI
- https://doi.org/10.5281/zenodo.22130538
- Primary Topic
- Cloud Data Security Solutions
- Type
- article
- Field-Weighted Citation Impact
- 0.00