Proceedings of the International scientific and practical conference ―Oxford 2026: Science and Education Today‖ (May 29-31, 2026) / Publisher website: www.naukainfo.com. - Oxford, United Kingdom, 2026. - 392 p.
187 domain [5]. At the network level, it is advisable to use intrusion detection systems with analysis of behavioral patterns of sessions, as well as the implementation of Zero Trust with continuous verification of each request regardless of authentication status. Summarizing all of the above, session interception and real-time proxy AiTM attacks form one of the most dangerous categories of modern cyberthreats , as they allow to effectively bypass traditional protections, including MFA . TOTP -based MFA is insufficient to protect against AiTM attacks and needs to be replaced or supplemented by other methods, detecting such attacks requires the integration of UEBA systems and analysis of behavioral anomalies of sessions. Therefore, comprehensive protection should combine cryptographically strong authentication methods, proper session management and Zero architecture Trust . REFERENCES: 1. Microsoft Digital Defense Report 2024. Microsoft Corporation. 2024. URL: https://www.microsoft.com/en-us/security/security-insider/threat- landscape/microsoft-digital-defense-report-2024 2. Global Analysis of Adversary - in - the -Middle Phishing Threats . Sekoia.io Blog . 11.06.2025. URL: https://blog.sekoia.io/global-analysis-of-adversary-in- the-middle-phishing-threats 3. Detection system threats to IoT devices based on behavioral analysis / Khmelnytskyi national University . Khmelnytskyi , 2025. 1925 p. 4. Kikuchi H. Impact Assessment of Adversary - in - the -Middle Attack Evilginx Bypassing 2FA. Proceedings of the Fourth International Conference on Innovations in Computing Research (ICR'25). ICR 25 2025 / eds . K. Daimi , A. Alsadoon . Cham : Springer, 2025. ( Lecture Notes in Networks and Systems; Vol . 1487). DOI: https://doi.org/10.1007/978-3-031-95652-2_14. 5. Grammatopoulos AV Blind software-assisted conformity and security assessment of FIDO2/ WebAuthn implementations / AV Grammatopoulos , I.
Made with FlippingBook
RkJQdWJsaXNoZXIy MTAxMzIwNA==