ANALYSIS OF CREDENTIAL STUFFING & PASSWORD SPRAYING ATTACK MODELS AND A DEFENSE-IN-DEPTH STRATEGY FOR HIGHER EDUCATION MANAGEMENT SYSTEMS | IJCSE Volume 10 – Issue 4 | IJCSE-V10I4P14
IJCSE
International Journal of Computer Science Engineering Techniques
ISSN 2455-135X · Peer-Reviewed · Open Access
📚 Volume 10, Issue 4
📅 August 27, 2026
📄 Pages 114–118
🔖 ID: IJCSE-V10I4P14
Table of Contents
ToggleANALYSIS OF CREDENTIAL STUFFING & PASSWORD SPRAYING ATTACK MODELS AND A DEFENSE-IN-DEPTH STRATEGY FOR HIGHER EDUCATION MANAGEMENT SYSTEMS
Author(s)
Nguyen Thi Hong Mai, Nguyen Manh Hung, Bui Thi Thuy Quynh
Abstract
In the digital transformation of higher education, academic management portals and Learning Management Systems (LMS) have become primary targets for automated cyberattacks. Although server-side password storage hashing algorithms such as Bcrypt or Scrypt have proven effective against database offline cracking, they remain largely ineffective against password enumeration attacks executed through legitimate authentication flows, specifically Credential Stuffing and Password Spraying. This paper presents an in-depth analysis of the theoretical models of Credential Stuffing and Password Spraying, highlighting system vulnerabilities and specific security risks inherent to the higher education environment. On this basis, the study proposes a 4-layer Defense-in-Depth Architecture consisting of independent yet complementary control layers, integrating security standards from OWASP and NIST. The research findings contribute a solid theoretical foundation to assist educational institutions in optimizing their information security infrastructure without compromising the digital user experience.
Keywords
Credential Stuffing, Password Spraying, Defense-in-Depth, Academic Management Systems, Higher Education Information Security, NIST, OWASP
Conclusion
Automated threats such as Credential Stuffing and Password Spraying represent major risks to student account security and system integrity in higher education environments. Sole reliance on server-side database password hashing is no longer sufficient. This paper has provided an in-depth analysis of these attack vectors and introduced a 4-layer Defense-in-Depth Architecture. The proposed solution enhances the security posture of higher education management platforms and offers a reference architecture for academic institutions pursuing secure, sustainable digital transformation.
References
[1] Le Dac Nhuong (2018), Data Security, Vietnam National University Press, Hanoi.
[2] Nguyen Van Tuan, Nguyen Hong Son (2022), Performance and Security Evaluation of Password Hashing Algorithms in E-Learning Systems, Journal of ICT.
[3] NIST (2020), Digital Identity Guidelines: Authentication and Lifecycle Management, NIST Special Publication 800-63B, National Institute of Standards and Technology.
[4] OWASP (2021), OWASP Automated Threat Handbook for Web Applications, Open Web Application Security Project.
[5] Shay, R., et al. (2016), Designing Password Policies for Strength and Usability, ACM Transactions on Information and System Security (TISSEC).
[2] Nguyen Van Tuan, Nguyen Hong Son (2022), Performance and Security Evaluation of Password Hashing Algorithms in E-Learning Systems, Journal of ICT.
[3] NIST (2020), Digital Identity Guidelines: Authentication and Lifecycle Management, NIST Special Publication 800-63B, National Institute of Standards and Technology.
[4] OWASP (2021), OWASP Automated Threat Handbook for Web Applications, Open Web Application Security Project.
[5] Shay, R., et al. (2016), Designing Password Policies for Strength and Usability, ACM Transactions on Information and System Security (TISSEC).
📋 How to Cite This Paper
Nguyen Thi Hong Mai, Nguyen Manh Hung, Bui Thi Thuy Quynh (2026). ANALYSIS OF CREDENTIAL STUFFING & PASSWORD SPRAYING ATTACK MODELS AND A DEFENSE-IN-DEPTH STRATEGY FOR HIGHER EDUCATION MANAGEMENT SYSTEMS. International Journal of Computer Science Engineering Techniques, 10(4), 114–118. ISSN: 2455-135X. DOI: https://doi.org/10.5281/zenodo.22130539

