短论文:前缀计数限制可能提高补发卡中的首次命中发现率
Short Paper: Prefix Count Limits Can Increase First-Hit Discovery in Card Reissuance
浏览论文内容
中文总结 AI 辅助
研究卡号泄露后发卡机构通过降低前缀计数来降低枚举风险的做法,发现该策略可能适得其反,在特定条件下反而增加攻击者发现有效卡号的概率。
中文摘要 AI 辅助
当卡号被泄露时,攻击者可能会搜索共享其前缀的有效卡号。发卡机构可能通过将卡从高密度前缀重新发放到低密度前缀来应对。我们表明,这种直观的计数控制可能适得其反。对于固定的搜索区域、暴露权重和总活动量,我们精确推导出在何种情况下降低最大前缀计数会增加有预算的搜索找到有效卡号的机会。在包含50,000个候选者的匹配合成模拟中,针对性的替换在每次运行中都满足计数限制,但在十二种设置中的三种情况下,相对于等量随机替换,提高了提供12位前缀的发现率。因此,较低的前缀计数本身并不能证明枚举风险较低。
英文摘要
When a card number is compromised, an attacker may search for active numbers sharing its prefix. An issuer might respond by reissuing cards from heavily populated prefixes into less populated ones. We show that this intuitive count control can backfire. For fixed search regions, exposure weights, and total activity, we derive exactly when reducing the maximum prefix count increases the chance that a budgeted search finds an active number. In matched synthetic simulations over 50,000 candidates, targeted replacement meets the count limit in every run but raises supplied-12-digit-prefix discovery relative to equal-volume random replacement in three of twelve settings. Thus a lower prefix count does not by itself certify lower enumeration risk.
发表机构
- BRAC University(布拉格大学)
机构由 AI 辅助整理,请以论文原文为准。