When Your Fitness Tracker Betrays You: Quantifying the Predictability of Biometric Features Across Contexts

When Your Fitness Tracker Betrays You: Quantifying the Predictability of Biometric Features Across Contexts
复制标题

DOI:
10.1109/sp.2018.00053
复制
发表时间:
2018-05
期刊:
2018 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Simon Eberz;Giulio Lovisotto;A. Patané;M. Kwiatkowska;Vincent Lenders;I. Martinovic
Simon Eberz;Giulio Lovisotto;A. Patané;M. Kwiatkowska;Vincent Lenders;I. Martinovic
中科院分区:
其他
文献类型:
--
作者:
Simon Eberz;Giulio Lovisotto;A. Patané;M. Kwiatkowska;Vincent Lenders;I. Martinovic

文献摘要

被引文献

相似文献

对行为生物识别技术的攻击变得越来越流行。大多数研究都集中在将先前获得的特征向量呈现给生物特征传感器,通常是由攻击者训练自己改变行为以匹配受害者的行为。然而,获得受害者的生物特征信息可能并不容易,特别是当认证设备上的用户模板被充分保护时。因此,如果认证设备不可访问,则攻击者可能必须从其他地方获取数据。在本文中,我们提出了一个分析框架,使我们能够衡量如何容易的功能可以预测的基础上收集的数据在不同的背景下(例如,不同的传感器、执行的任务或环境)。该框架用于评估单个特征或整个生物特征对此类跨上下文攻击的弹性。为了能够比较现有的生物特征,我们进行了一项用户研究,从30名参与者和5个生物特征(ECG,眼球运动,鼠标运动,触摸屏动态和步态)在各种情况下收集生物特征数据。我们在网上公开了这个数据集。我们的结果表明,许多攻击场景在实践中是可行的,因为可以从各种背景中轻松预测特征。所有生物特征都包括特别可预测的特征(例如,ECG的幅度特征或鼠标移动的曲率)。总体而言,我们观察到,对眼球运动,鼠标运动和触摸屏输入的跨上下文攻击相对容易,而ECG和步态表现出更混乱的跨上下文变化。
Attacks on behavioral biometrics have become increasingly popular. Most research has been focused on presenting a previously obtained feature vector to the biometric sensor, often by the attacker training themselves to change their behavior to match that of the victim. However, obtaining the victim's biometric information may not be easy, especially when the user's template on the authentication device is adequately secured. As such, if the authentication device is inaccessible, the attacker may have to obtain data elsewhere. In this paper, we present an analytic framework that enables us to measure how easily features can be predicted based on data gathered in a different context (e.g., different sensor, performed task or environment). This framework is used to assess how resilient individual features or entire biometrics are against such cross-context attacks. In order to be able to compare existing biometrics with regard to this property, we perform a user study to gather biometric data from 30 participants and five biometrics (ECG, eye movements, mouse movements, touchscreen dynamics and gait) in a variety of contexts. We make this dataset publicly available online. Our results show that many attack scenarios are viable in practice as features are easily predicted from a variety of contexts. All biometrics include features that are particularly predictable (e.g., amplitude features for ECG or curvature for mouse movements). Overall, we observe that cross-context attacks on eye movements, mouse movements and touchscreen inputs are comparatively easy while ECG and gait exhibit much more chaotic cross-context changes.