Skip to content
Open access

The Erosion of Password-Based Authentication Security: A Data-Driven Evaluation of Phishing-Based Session Hijacking and MFA-Bypass Techniques

2026 · International journal of research and scientific innovation · 0 citations

Abstract

Password authentication remains widely used, but modern phishing campaigns increasingly target the authenticated session rather than the password alone. This study examines the gradual erosion of password-based security through a reproducible secondary-data analysis of phishing websites and network intrusions, while also assessing whether commonly used public datasets can support claims about phishing-based session hijacking and multifactor authentication (MFA) bypass. Three datasets formed the basis of the analysis. The UCI Phishing Websites dataset contained 11,055 records and 30 predictors, while the Vrbančič phishing dataset included 88,647 records and 111 predictors. The third dataset was a documented random sample from CICIDS2017, made up of 56,661 network flows and 77 predictors. Both logistic regression and random forest were tested using a hold-out method with an 80/20 split. The F1 scores for random forest algorithm were 0.972 and 0.957 for the two phishing detection datasets, and 0.996 for the binary classification of the CICIDS2017. Overall, random forest showed excellent results, with 0.994 accuracy and 0.980 macro-F1 in the case of a multi-class CICIDS2017 task. The results for the Infiltration class should be further verified, as the test set appears to have only seven instances of this class. Feature importance was largely driven by webpage, URL, domain, and network-flow characteristics. However, none of the analyzed datasets included MFA challenge events, session-cookie issuance, token capture, token replay, device binding, or post-authentication identity telemetry. A structured observability audit therefore found direct coverage for only three of the seven stages in the proposed compromise chain. These results show that strong phishing and intrusion classifiers can identify conditions that enable an attack, but they cannot, on their own, demonstrate the detection of session hijacking or MFA bypass. A more complete evaluation requires the integration of phishing, identity-provider, endpoint, and session telemetry.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.