An Empirical Evaluation of Online Continuous Authentication and Anomaly Detection Using Mouse Clickstream Data Analysis

An Empirical Evaluation of Online Continuous Authentication and Anomaly Detection Using Mouse Clickstream Data Analysis
复制标题

DOI:
10.3390/app11136083
复制
发表时间:
2021-07-01
影响因子:
2.7
通讯作者:
Roy, Kaushik
Roy, Kaushik
中科院分区:
综合性期刊4区
文献类型:
--
作者:
Almalki, Sultan;Assery, Nasser;Roy, Kaushik

文献摘要

被引文献

相似文献

虽然在社交网络、电子邮件、电子商务和网上银行中使用的基于密码的身份验证容易受到黑客攻击,但基于生物识别的连续身份验证系统已成功用于处理未经授权访问的增加。在这项研究中,在线连续认证(CA)和异常检测(AD)的基础上鼠标点击流数据分析的实证评估。这项研究首先通过使用用于收集鼠标信息的软件从20名参与者那里收集了一组在线鼠标动态信息,从原始数据集中提取了大约87个特征。与以前的工作相比,CA和AD的效率使用不同的机器学习(ML)和深度学习(DL)算法进行了研究,即决策树分类器(DT),k-最近邻分类器(KNN),随机森林分类器(RF)和卷积神经网络分类器(CNN)。通过使用三个场景来确定用户标识:场景A,单个鼠标移动动作;场景B,单个点击动作;以及场景C,一组鼠标移动和点击动作。结果表明,每个分类器都能够区分真实用户和欺诈用户,具有较高的准确度。
While the password-based authentication used in social networks, e-mail, e-commerce, and online banking is vulnerable to hackings, biometric-based continuous authentication systems have been used successfully to handle the rise in unauthorized accesses. In this study, an empirical evaluation of online continuous authentication (CA) and anomaly detection (AD) based on mouse clickstream data analysis is presented. This research started by gathering a set of online mouse-dynamics information from 20 participants by using software developed for collecting mouse information, extracting approximately 87 features from the raw dataset. In contrast to previous work, the efficiency of CA and AD was studied using different machine learning (ML) and deep learning (DL) algorithms, namely, decision tree classifier (DT), k-nearest neighbor classifier (KNN), random forest classifier (RF), and convolutional neural network classifier (CNN). User identification was determined by using three scenarios: Scenario A, a single mouse movement action; Scenario B, a single point-and-click action; and Scenario C, a set of mouse movement and point-and-click actions. The results show that each classifier is capable of distinguishing between an authentic user and a fraudulent user with a comparatively high degree of accuracy.