When Human cognitive modeling meets PINs: User-independent inter-keystroke timing attacks

When Human cognitive modeling meets PINs: User-independent inter-keystroke timing attacks
复制标题

DOI:
10.1016/j.cose.2018.09.003
复制
发表时间:
2018-10
期刊:
ArXiv
影响因子:
--
通讯作者:
Ximing Liu;Yingjiu Li;R. Deng;Bing Chang;Shujun Li
Ximing Liu;Yingjiu Li;R. Deng;Bing Chang;Shujun Li
中科院分区:
其他
文献类型:
--
作者:
Ximing Liu;Yingjiu Li;R. Deng;Bing Chang;Shujun Li

文献摘要

被引文献

相似文献

本文提出了第一个独立于用户的PINs码间定时攻击。我们的攻击方法是基于一个跨时间字典从人类认知模型,其参数可以确定的任何用户(不一定是目标受害者)的少量训练数据。因此,我们的攻击可能会在现实世界中大规模发起。我们研究了不同在线攻击环境下的跨节点定时攻击,并评估了它们在不同强度水平下对PIN的性能。我们的实验结果表明,所提出的攻击性能显着优于随机猜测攻击。我们进一步证明了我们的攻击对现实世界的应用程序构成了严重的威胁,并提出了各种方法来减轻威胁。
This paper proposes the first user-independent inter-keystroke timing attacks on PINs. Our attack method is based on an inter-keystroke timing dictionary built from a human cognitive model whose parameters can be determined by asmallamount of training data on any users (not necessarily the target victims). Our attacks can thus be potentially launched on a large scale in real-world settings. We investigate inter-keystroke timing attacks in different online attack settings and evaluate their performance on PINs at different strength levels. Our experimental results show that the proposed attack performs significantly better than random guessing attacks. We further demonstrate that our attacks pose a serious threat to real-world applications and propose various ways to mitigate the threat.