ANALYSIS OF CREDENTIAL STUFFING & PASSWORD SPRAYING ATTACK MODELS AND A DEFENSE-IN-DEPTH STRATEGY FOR HIGHER EDUCATION MANAGEMENT SYSTEMS

In the digital transformation of higher education, academic management portals and Learning Management Systems (LMS) have become primary targets for automated cyberattacks. Although server-side password storage hashing algorithms such as Bcrypt or Scrypt have proven effective against database offline cracking, they remain largely ineffective against password enumeration attacks executed through legitimate authentication flows, specifically Credential Stuffing and Password Spraying. This paper presents an in-depth analysis of the theoretical models of Credential Stuffing and Password Spraying, highlighting system vulnerabilities and specific security risks inherent to the higher education environment. On this basis, the study proposes a 4-layer Defense-in-Depth Architecture consisting of independent yet complementary control layers, integrating security standards from OWASP and NIST. The research findings contribute a solid theoretical foundation to assist educational institutions in optimizing their information security infrastructure without compromising the digital user experience.

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-08-27
DOI
https://doi.org/10.5281/zenodo.22130538
Primary Topic
Cloud Data Security Solutions
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

ANALYSIS OF CREDENTIAL STUFFING & PASSWORD SPRAYING ATTACK MODELS AND A DEFENSE-IN-DEPTH STRATEGY FOR HIGHER EDUCATION MANAGEMENT SYSTEMS

Bùi Thị Thuý Quỳnh, Nguyen Thi Hong Mai, Nguyen Manh Hung
Zenodo (CERN European Organization for Nuclear Research)
Cloud Data Security Solutions
article

ANALYSIS OF CREDENTIAL STUFFING & PASSWORD SPRAYING ATTACK MODELS AND A DEFENSE-IN-DEPTH STRATEGY FOR HIGHER EDUCATION MANAGEMENT SYSTEMS

Bùi Thị Thuý Quỳnh, Nguyen Thi Hong Mai, Nguyen Manh Hung
article en

Abstract

In the digital transformation of higher education, academic management portals and Learning Management Systems (LMS) have become primary targets for automated cyberattacks. Although server-side password storage hashing algorithms such as Bcrypt or Scrypt have proven effective against database offline cracking, they remain largely ineffective against password enumeration attacks executed through legitimate authentication flows, specifically Credential Stuffing and Password Spraying. This paper presents an in-depth analysis of the theoretical models of Credential Stuffing and Password Spraying, highlighting system vulnerabilities and specific security risks inherent to the higher education environment. On this basis, the study proposes a 4-layer Defense-in-Depth Architecture consisting of independent yet complementary control layers, integrating security standards from OWASP and NIST. The research findings contribute a solid theoretical foundation to assist educational institutions in optimizing their information security infrastructure without compromising the digital user experience.

Zenodo (CERN European Organization for Nuclear Research)
Industry, innovation and infrastructure
Openalex Percentile: Top 3%
Cloud Data Security Solutions
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.