Articles
| Open Access |
DOI:
https://doi.org/10.55640/ijcsis/Volume11Issue09-01
Attack Surface Analysis of Federated SSO and Multi-Factor Authentication Systems Using the STRIDE Framework
Hiroshi Nakamura , Department of Data Science and Intelligent Systems, Advanced Computing Research Institute, Tokyo, JapanAbstract
Federated Single Sign-On (SSO) and Multi-Factor Authentication (MFA) systems have become fundamental components of modern identity and access management architectures because they reduce credential duplication while enabling centralized authentication across multiple applications and organizational domains. However, federation introduces complex trust relationships among identity providers, service providers, authentication protocols, tokens, sessions, and user devices, creating an attack surface that cannot be adequately assessed by examining individual authentication components in isolation. This research examines the attack surface of federated SSO and MFA systems through a STRIDE-oriented threat modeling perspective. The methodology decomposes the authentication ecosystem into identity, protocol, token, session, endpoint, and trust-boundary components and evaluates potential threats involving spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. The analytical approach is informed by the supplied literature on feature selection, sparse modeling, classification, statistical discrimination, and high-dimensional data analysis, which provides theoretical foundations for reducing complex threat spaces into interpretable risk dimensions. The analysis demonstrates that federation can simultaneously improve centralized security governance and increase systemic dependency on identity infrastructure. MFA reduces several credential-related risks but does not eliminate attacks against authentication workflows, tokens, sessions, recovery mechanisms, or federation trust relationships. The study proposes a structured attack-surface model in which threat prioritization is based on component criticality, trust-boundary exposure, attack-path concentration, and potential privilege impact. The findings emphasize that effective federated authentication security requires security assessment beyond login mechanisms and must incorporate the complete identity transaction lifecycle.
Keywords
Federated SSO, Multi-Factor Authentication, STRIDE, Threat Modeling
References
Boulesteix AL, Strimmer K (2006). Partial least squares: A versatile tool for the analysis of high-dimensional genomic data. Briefings in Bioformatics, 8: 32–44.
Chun H, Keleş S (2010). Sparse partial least squares regression for simultaneous dimension reduction and variable selection. Journal of the Royal Statistical Society Series B: Statistical Methodology, 72(1): 3–25.
Chung D, Keles S (2010). Sparse partial least squares classification for high dimensional data. Statistical Applications in Genetics and Molecular Biology, 9. Article 17.
De Jong S (1993). Simpls: An alternative approach to partial least squares regression. Chemometrics and Intelligent Laboratory Systems, 18: 251–263.
Fan J, Li R (2001). Variable selection via nonconcave penalized likelihood and its oracle properties. Journal of the American Statistical Association, 96: 1348–1360.
Fan J, Samworth R, Wu Y (2009). Ultrahigh dimensional feature selection: Beyond the linear model. Journal of Machine Learning Research, 10: 2013–2038.
Fanty M, Cole R (1990). Spoken letter recognition. Proceedings of the International Conference on Neural Information Processing Systems, 4: 220–226.
Fisher RA (1936). The use of multiple measurements in taxonomic problems. Annals of Eugenics, 7(2): 179–188.
Freeman C, Kulić D, Basir O (2013). Feature-selected tree-based classification. IEEE Transactions on Cybernetics, 43(6): 1990–2004.
Friedman J, Hastie T, Tibshirani R (2010). Regularization paths for generalized linear models via coordinate descent. Journal of Statistical Software, 33(1): 1.
Ganapathy, S. K. . (2024). Threat Modeling for Federated SSO and MFA Systems: STRIDE-Based Analysis of Attack Vectors. International Journal of Data Science and Machine Learning, 4(02), 55-73.
Hoskuldsson A (1988). PLS regression methods. Journal of Chemometrics, 2: 211–228.
Hoskuldsson A (1992). The h-principle in modelling with applications to chemometrics. Chemometrics and Intelligent Laboratory Systems, 14: 139–153.
Hutter C, Zenklusen JC (2018). The Cancer Genome Atlas: Creating lasting value beyond its data. Cell, 173(2): 283–285.
Johnstone IM, Silverman BW (2004). Needles and straw in haystacks: Empirical Bayes estimates of possibly sparse sequences. The Annals of Statistics, 32(4): 1594–1649.
Lê Cao KA, Rossouw D, Robert-Granié C, Besse P (2008). A sparse PLS for variable selection when integrating omics data. Statistical Applications in Genetics and Molecular Biology. 7(1): Article 35.
Lin Y, Zhang M, Zhang D (2015). Generalized orthogonal components regression for high dimensional generalized linear models. Computational Statistics & Data Analysis, 88: 119–127.
Loh WY (2011). Classification and regression trees. Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery, 1(1): 14–23.
Massy WF (1965). Principal components regression in exploratory statistical research. Journal of the American Statistical Association, 60(309): 234–256.
McLachlan GJ (2005). Discriminant Analysis and Statistical Pattern Recognition. John Wiley & Sons.
Nguyen DV, Rocke DM (2002a). Classification of Acute Leukemia Based on DNA Microarray Gene Expressions Using Partial Least Squares. Springer.
Nguyen DV, Rocke DM (2002b). Tumor classification by partial least squares using microarray gene expression data. Bioinformatics, 18: 39–50.
Shen J, Gao S (2008). A solution to separation and multicollinearity in multiple logistic regression. Journal of Data Science, 6(4): 515.
Tam V, Patel N, Turcotte M, Bossé Y, Paré G, Meyre D (2019). Benefits and limitations of genome-wide association studies. Nature Reviews. Genetics, 20(8): 467–484.
Ganapathy, S. K. (2024). Threat Modeling for Federated SSO and MFA Systems: STRIDE-Based Analysis of Attack Vectors. International Journal of Data Science and Machine Learning, 4(02), 55-73. https://www.academicpublishers.org/journals/index.php/ijdsml/article/view/stride-analysis-sso-mfa
Article Statistics
Downloads
Copyright License
Copyright (c) 2026 Hiroshi Nakamura

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.
Copyright and Ethics:
- Authors are responsible for obtaining permission to use any copyrighted materials included in their manuscript.
- Authors are also responsible for ensuring that their research was conducted in an ethical manner and in compliance with institutional and national guidelines for the care and use of animals or human subjects.
- By submitting a manuscript to International Journal of Computer Science & Information System (IJCSIS), authors agree to transfer copyright to the journal if the manuscript is accepted for publication.