A User Study of Keystroke Dynamics as Second Factor in Web MFA

A User Study of Keystroke Dynamics as Second Factor in Web MFA
复制标题

击键动力学作为 Web MFA 中第二因素的用户研究

DOI:
10.1145/3577923.3583642
复制
发表时间:
2023
期刊:
CODASPY '23: Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
Schuckers, Stephanie
Schuckers, Stephanie
中科院分区:
--
文献类型:
--
作者:
Wahab, Ahmed Anu;Hou, Daqing;Schuckers, Stephanie

文献摘要

参考文献

被引文献

相似文献

随着帐户泄露和恶意在线攻击的增加,已采用多因素身份验证(MFA)来防御这些攻击。OTP和移动的推送通知只是普遍采用的MFA因素的两个示例。虽然MFA提高了安全性,但它们也向身份验证过程添加了额外的步骤或硬件,从而增加了身份验证时间并引入了摩擦。另一方面,基于动态的身份验证被认为是一种有前途的MFA,可以在减少摩擦的同时提高安全性。虽然已经有一些关于其他MFA因素的可用性的研究,但尚未研究过动态的可用性。为此,我们构建了一个Web身份验证系统,该系统具有注册,登录和帐户恢复的标准功能,并集成了作为附加因素的动态身份验证。然后,我们对该系统进行了用户研究,其中20名参与者完成了与注册,登录和帐户恢复相关的任务。我们还评估了一种新的方法来完成用户注册过程,该方法通过自然地采用其他替代MFA因素(在我们的研究中为OTP)来减少摩擦,当MFA动力学尚未准备好使用时。我们的研究表明,在保持强安全性(0% FPR)的同时,添加动态身份验证减少了身份验证摩擦,避免了登录时66.3%的OTP和帐户恢复时85.8%的OTP,从而分别减少了登录和帐户恢复的身份验证时间63.3%和78.9%。通过一项退出调查,所有参与者都认为,将身份验证动态与一次性身份验证相结合比传统的一次性身份验证更可取。
As account compromises and malicious online attacks are on the rise, multi-factor authentication (MFA) has been adopted to defend against these attacks. OTP and mobile push notification are just two examples of the popularly adopted MFA factors. Although MFA improve security, they also add additional steps or hardware to the authentication process, thus increasing the authentication time and introducing friction. On the other hand, keystroke dynamics-based authentication is believed to be a promising MFA for increasing security while reducing friction. While there have been several studies on the usability of other MFA factors, the usability of keystroke dynamics has not been studied. To this end, we have built a web authentication system with the standard features of signup, login and account recovery, and integrated keystroke dynamics as an additional factor. We then conducted a user study on the system where 20 participants completed tasks related to signup, login and account recovery. We have also evaluated a new approach for completing the user enrollment process, which reduces friction by naturally employing other alternative MFA factors (OTP in our study) when keystroke dynamics is not ready for use. Our study shows that while maintaining strong security (0% FPR), adding keystroke dynamics reduces authentication friction by avoiding 66.3% of OTP at login and 85.8% of OTP at account recovery, which in turn reduces the authentication time by 63.3% and 78.9% for login and account recovery respectively. Through an exit survey, all participants have rated the integration of keystroke dynamics with OTP to be more preferable to the conventional OTP-only authentication.
击键认证算法的基准测试
DOI: --
发表时间: 2017
期刊: International Workshop on Information Forensics and Security
影响因子: --
作者:
Jiaju Huang;Daqing Hou;S. Schuckers;Timothy Law;Adam Sherwin
通讯作者: Adam Sherwin
共享多键盘和双语数据集以支持击键动力学研究
DOI: 10.1145/3508398.3511516
发表时间: 2022
期刊: CODASPY '22: Proceedings of the Twelfth ACM Conference on Data and Application Security and Privacy
影响因子: --
作者:
Wahab, Ahmed Anu;Hou, Daqing;Banavar, Mahesh;Schuckers, Stephanie;Eaton, Kenneth;Baldwin, Jacob;Wright, Robert
通讯作者: Wright, Robert