Mitigating real-time phishing in Time-based One-Time Password applications using behavioral analysis

dc.contributor.authorKivuva, J. L.
dc.date.accessioned2026-04-20T16:33:15Z
dc.date.issued2025
dc.descriptionFull - text thesis
dc.description.abstractTime-based One-Time Password (TOTP) applications enhance online security by providing an additional authentication layer. However, they are vulnerable to real-time phishing attacks, where attackers deceive users into entering their TOTP codes on fraudulent websites. Since TOTP codes are valid for a short duration and cannot be reused, traditional security mechanisms struggle to detect and prevent their misuse in real-time. Attackers can intercept these codes and immediately use them to gain unauthorized access before they expire, bypassing standard authentication defenses. This dissertation presents a behavioral analysis approach to mitigate real-time phishing attacks on TOTP systems. An algorithm was designed to detect suspicious activity by analyzing user behavior patterns, such as login frequency, location, device type, and interaction anomalies. The algorithm flags potential phishing attempts in real-time by establishing a baseline for normal usage and identifying deviations. A proof-of-concept prototype was developed using a data-driven prototyping methodology to validate the effectiveness of this approach. The results confirm that integrating behavioral analysis into TOTP applications provides proactive security by detecting and responding to phishing threats before authentication codes are exploited. Keywords: Time-based One-Time Passwords, Behavioral Analysis, Real-Time Phishing, Authentication
dc.identifier.citationKivuva, J. L. (2025). Mitigating real-time phishing in Time-based One-Time Password applications using behavioral analysis [Strathmore University]. https://hdl.handle.net/11071/16402
dc.identifier.urihttps://hdl.handle.net/11071/16402
dc.language.isoen
dc.publisherStrathmore University
dc.titleMitigating real-time phishing in Time-based One-Time Password applications using behavioral analysis
dc.typeThesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Mitigating real-time phishing in Time-based One-Time Password applications using behavioral analysis.pdf
Size:
3.09 MB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: