Evaluating the Reliability of Credential Hardening through Keystroke Dynamics

Evaluating the Reliability of Credential Hardening through Keystroke Dynamics
复制标题

通过击键动力学评估凭证强化的可靠性

DOI:
10.1109/issre.2006.25
复制
发表时间:
2006
期刊:
2006 17th International Symposium on Software Reliability Engineering
影响因子:
--
通讯作者:
B. Cukic
B. Cukic
中科院分区:
--
文献类型:
--
作者:
Nick Bartlow;B. Cukic

文献摘要

被引文献

相似文献

大多数计算机系统依赖于用户名和密码作为身份验证和访问控制的机制。这些凭证集为具有不同敏感性级别的广泛应用程序提供弱保护。传统的生理生物识别系统,如指纹,人脸和虹膜识别是不容易部署在远程认证方案。击键动态提供了将用户名/密码方案的易用性与生物测定相关联的增加的可信度相结合的联合收割机。我们的研究通过结合换档键模式扩展了之前关于击键力学的工作。该系统能够在传统ROC曲线上的各个点上运行,具体取决于应用程序的特定安全需求。1%的错误接受率可以在14%的错误拒绝率下实现。5%的相等错误率适合于要求相对低安全性的系统。作为一个用户名密码认证方案,我们的方法降低了95%-99%的系统渗透率与妥协的密码。所述性能测量可以通过在用户特定的基础上优化分类算法来进一步改进
Most computer systems rely on usernames and passwords as a mechanism for authentication and access control. These credential sets offer weak protection to a broad scope of applications with differing levels of sensitivity. Traditional physiological biometric systems such as fingerprint, face, and iris recognition are not readily deployable in remote authentication schemes. Keystroke dynamics provide the ability to combine the ease of use of username/password schemes with the increased trustworthiness associated with biometrics. Our research extends previous work on keystroke dynamics by incorporating shift-key patterns. The system is capable of operating at various points on a traditional ROC curve depending on application specific security needs. A 1% false accept rate is attainable at a 14% false reject rate. An equal error rate of 5% is suitable for systems requiring a relatively low security. As a username password authentication scheme, our approach decreases the system penetration rate associated with compromised passwords by 95%-99%. Said performance measures can be further improved through optimization of the classification algorithm on a user specific basis