A Multi-layered Security Framework for Protecting Authentication Link Generation APIs through Integrated Defence in Depth Mechanisms
|
Researchers |
Nadim Ibrahim and Anas Alrajh |
|
Published in |
International Journal of Intelligent Engineering and Systems, volume 19, issue 5, pp. 985-1004, May 2026. |
|
Abstract |
The exponential proliferation of Application Programming Interfaces (APIs) in contemporary authentication ecosystems has engendered substantial security vulnerabilities, particularly for publicly exposed endpoints that facilitate temporary authentication link generation for mobile authenticator applications. This paper presents ML-AuthGuard, a comprehensive multi-layered security framework that synergistically integrates defence mechanisms across infrastructure, behavioural, cryptographic, and protocol layers to protect authentication link generation APIs against sophisticated and evolving attack vectors. The proposed framework introduces four principal innovations: an adaptive rate-limiting mechanism with dynamic IP restriction policies leveraging real-time threat intelligence, a behavioural analysis module incorporating adaptive reCAPTCHA challenges with multi-modal device fingerprinting, a novel Cryptographic Nonce Binding Protocol (CNB-Protocol) that cryptographically links authentication tokens to client fingerprints and temporal constraints, and enhanced web security policies through strict Cross-Origin Resource Sharing (CORS) enforcement and iframe embedding prevention. Rigorous experimental evaluation across 30 days of continuous operation with over 10 million requests demonstrates that ML-AuthGuard achieves a 97.73% overall attack detection rate with only 0.15% false positive rate, including 100% detection of replay attacks, while maintaining acceptable user experience with an average authentication latency increase of only 25.8%. Comparative analysis against five existing security solutions validates the superiority of the integrated defence in depth approach over single-layer implementations. Key words: API security, Authentication systems, Multi-layered defence, Cryptographic nonce binding, Device fingerprinting, Replay attack prevention, OAuth 2.0, Zero-trust architecture, Behavioural analysis, Adaptive CAPTCHA. |
|
Link to full paper |
https://inass.org/wp-content/uploads/2026/02/2026053156-2.pdf |