The Erosion of Password-Based Authentication Security: A Data-Driven Evaluation of Phishing-Based Session Hijacking and MFA-Bypass Techniques
Authors
State University of Northern Negros (Philippines)
State University of Northern Negros (Philippines)
State University of Northern Negros (Philippines)
State University of Northern Negros (Philippines)
State University of Northern Negros (Philippines)
State University of Northern Negros (Philippines)
State University of Northern Negros (Philippines)
Article Information
DOI: 10.51244/IJRSI.2026.1307000331
Subject Category: Criminology
Volume/Issue: 13/7 | Page No: 4518-4528
Publication Timeline
Submitted: 2026-08-01
Accepted: 2026-08-06
Published: 2026-08-18
Abstract
Password authentication remains widely used, but modern phishing campaigns increasingly target the authenticated session rather than the password alone. This study examines the gradual erosion of password-based security through a reproducible secondary-data analysis of phishing websites and network intrusions, while also assessing whether commonly used public datasets can support claims about phishing-based session hijacking and multifactor authentication (MFA) bypass. Three datasets formed the basis of the analysis. The UCI Phishing Websites dataset contained 11,055 records and 30 predictors, while the Vrbančič phishing dataset included 88,647 records and 111 predictors. The third dataset was a documented random sample from CICIDS2017, made up of 56,661 network flows and 77 predictors. Both logistic regression and random forest were tested using a hold-out method with an 80/20 split. The F1 scores for random forest algorithm were 0.972 and 0.957 for the two phishing detection datasets, and 0.996 for the binary classification of the CICIDS2017. Overall, random forest showed excellent results, with 0.994 accuracy and 0.980 macro-F1 in the case of a multi-class CICIDS2017 task. The results for the Infiltration class should be further verified, as the test set appears to have only seven instances of this class. Feature importance was largely driven by webpage, URL, domain, and network-flow characteristics. However, none of the analyzed datasets included MFA challenge events, session-cookie issuance, token capture, token replay, device binding, or post-authentication identity telemetry. A structured observability audit therefore found direct coverage for only three of the seven stages in the proposed compromise chain. These results show that strong phishing and intrusion classifiers can identify conditions that enable an attack, but they cannot, on their own, demonstrate the detection of session hijacking or MFA bypass. A more complete evaluation requires the integration of phishing, identity-provider, endpoint, and session telemetry.
Keywords
authentication, phishing, hijacking, MFA bypass, machine learning
Downloads
References
1. Bonneau, J., Herley, C., van Oorschot, P. C., & Stajano, F. (2012). The quest to replace passwords: A framework for comparative evaluation of web authentication schemes. In 2012 IEEE Symposium on Security and Privacy (pp. 553-567). IEEE. https://doi.org/10.1109/SP.2012.44 [Google Scholar] [Crossref]
2. Cybersecurity and Infrastructure Security Agency. (2022). Implementing phishing-resistant MFA. U.S. Department of Homeland Security. https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf [Google Scholar] [Crossref]
3. D'Hooge, L. (n.d.-a). CIC-IDS2017 [Data set]. Kaggle. https://www.kaggle.com/datasets/dhoogla/cicids2017 [Google Scholar] [Crossref]
4. D'Hooge, L. (n.d.-b). CIC-IDS-Collection [Data set]. Kaggle. https://www.kaggle.com/datasets/dhoogla/cicidscollection [Google Scholar] [Crossref]
5. Engelen, G., Rimmer, V., & Joosen, W. (2021). Troubleshooting an intrusion detection dataset: The CICIDS2017 case study. In 2021 IEEE Security and Privacy Workshops (SPW) (pp. 7-12). IEEE. https://doi.org/10.1109/SPW53761.2021.00009 [Google Scholar] [Crossref]
6. Hannousse, A., & Yahiouche, S. (2021). Web page phishing detection [Data set]. Mendeley Data. https://doi.org/10.17632/c2gw7fy2j4.3 [Google Scholar] [Crossref]
7. Microsoft. (2022, July 12). From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud. Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud/ [Google Scholar] [Crossref]
8. Microsoft. (2023, June 8). Detecting and mitigating a multi-stage AiTM phishing and BEC campaign. Microsoft Security Blog. https://www.microsoft.com/en-us/security/blog/2023/06/08/detecting-and-mitigating-a-multi-stage-aitm-phishing-and-bec-campaign/ [Google Scholar] [Crossref]
9. Mohammad, R. M., & McCluskey, L. (2012). Phishing websites [Data set]. UCI Machine Learning Repository. https://doi.org/10.24432/C51W2X [Google Scholar] [Crossref]
10. Mohammad, R. M., Thabtah, F., & McCluskey, L. (2015). Tutorial and critical analysis of phishing websites methods. Computer Science Review, 17, 1-24. https://doi.org/10.1016/j.cosrev.2015.04.001 [Google Scholar] [Crossref]
11. Pedregosa, F., Varoquaux, G., Gramfort, A., Michel, V., Thirion, B., Grisel, O., Blondel, M., Prettenhofer, P., Weiss, R., Dubourg, V., Vanderplas, J., Passos, A., Cournapeau, D., Brucher, M., Perrot, M., & Duchesnay, E. (2011). Scikit-learn: Machine learning in Python. Journal of Machine Learning Research, 12, 2825-2830. https://www.jmlr.org/papers/v12/pedregosa11a.html [Google Scholar] [Crossref]
12. Sharafaldin, I., Lashkari, A. H., & Ghorbani, A. A. (2018). Toward generating a new intrusion detection dataset and intrusion traffic characterization. In Proceedings of the 4th International Conference on Information Systems Security and Privacy (pp. 108-116). SCITEPRESS. https://doi.org/10.5220/0006639801080116 [Google Scholar] [Crossref]
13. Temoshok, D., Fenton, J. L., Choong, Y.-Y., Lefkovitz, N., Regenscheid, A., Galluzzo, R., & Richer, J. P. (2025). Digital identity guidelines: Authentication and authenticator management (NIST Special Publication 800-63B-4). National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-63B-4 [Google Scholar] [Crossref]
14. Vrbančič, G., Fister, I., Jr., & Podgorelec, V. (2020). Datasets for phishing websites detection. Data in Brief, 33, Article 106438. https://doi.org/10.1016/j.dib.2020.106438 [Google Scholar] [Crossref]
15. Western OC2 Lab. (n.d.). Intrusion-Detection-System-Using-Machine-Learning [Data set and code repository]. GitHub. https://github.com/Western-OC2-Lab/Intrusion-Detection-System-Using-Machine-Learning [Google Scholar] [Crossref]
16. World Wide Web Consortium. (2021). Web authentication: An API for accessing public key credentials - Level 2 (W3C Recommendation). https://www.w3.org/TR/webauthn-2/ [Google Scholar] [Crossref]
Metrics
Views & Downloads
Similar Articles
- Occupational Culture in Relation to Job Satisfaction and Work Performance among Police
- Inmates' Character Reformation and Recidivism in Nigeria: A Study of Okaka Correctional Facility, Yenagoa, Bayelsa State.
- Life World of Former Female Basic Internal Security Operations Course (BISOC) Trainees
- Efficacy of Fingerprint and Facial Recognition in Enhancing National Security in Kenya
- No More Catcalling: Awareness of College of Criminal Justice Education Students on Republic Act 11313 Also Known as Safe Spaces Act