Examining a Large Keystroke Biometrics Dataset for Statistical-Attack Openings

Examining a Large Keystroke Biometrics Dataset for Statistical-Attack Openings
复制标题

DOI:
10.1145/2516960
复制
发表时间:
2013-09
期刊:
ACM Trans. Inf. Syst. Secur.
影响因子:
--
通讯作者:
Abdul Serwadda;V. Phoha
Abdul Serwadda;V. Phoha
中科院分区:
其他
文献类型:
--
作者:
Abdul Serwadda;V. Phoha

文献摘要

被引文献

相似文献

基于身份验证的研究传统上假设人类冒名顶替者通过在键盘上物理键入来生成身份验证。由于机器人现在已经被充分理解为有能力产生精确定时的攻击序列,这种攻击模式可能会低估基于机器人的系统在实践中面临的威胁。在这项工作中,我们将研究如何基于身份验证系统将执行,如果它受到合成攻击,旨在模仿典型的用户。为了实施攻击,我们对超过3000名用户在2年内收集的生物特征数据进行了严格的统计分析,然后使用观察到的统计特征来设计和发起针对三个最先进的基于密码的身份验证系统的算法攻击。相对于通常用于测试生物特征识别系统性能的零努力攻击,我们表明,我们的算法攻击将三个高性能生物特征识别验证器的平均等错误率(EER)提高了28.6%至84.4%。我们还发现,攻击的影响是更明显时,受到攻击的配置文件是基于较短的字符串,一些用户看到的攻击下比其他人更大的性能下降。本文呼吁从传统的零努力测试基于密码的身份验证程序的性能的方法转变为更严格的算法方法,以捕获当今机器人所构成的威胁。
Research on keystroke-based authentication has traditionally assumed human impostors who generate forgeries by physically typing on the keyboard. With bots now well understood to have the capacity to originate precisely timed keystroke sequences, this model of attack is likely to underestimate the threat facing a keystroke-based system in practice. In this work, we investigate how a keystroke-based authentication system would perform if it were subjected to synthetic attacks designed to mimic the typical user. To implement the attacks, we perform a rigorous statistical analysis on keystroke biometrics data collected over a 2-year period from more than 3000 users, and then use the observed statistical traits to design and launch algorithmic attacks against three state-of-the-art password-based keystroke verification systems. Relative to the zero-effort attacks typically used to test the performance of keystroke biometric systems, we show that our algorithmic attack increases the mean Equal Error Rates (EERs) of three high performance keystroke verifiers by between 28.6% and 84.4%. We also find that the impact of the attack is more pronounced when the keystroke profiles subjected to the attack are based on shorter strings, and that some users see considerably greater performance degradation under the attack than others. This article calls for a shift from the traditional zero-effort approach of testing the performance of password-based keystroke verifiers, to a more rigorous algorithmic approach that captures the threat posed by today’s bots.