Securing Account Recovery Mechanism on Desktop Computers and Mobile Phones with Keystroke Dynamics

Securing Account Recovery Mechanism on Desktop Computers and Mobile Phones with Keystroke Dynamics
复制标题

通过击键动力学保护台式计算机和移动电话上的帐户恢复机制

DOI:
10.1007/s42979-022-01245-3
复制
发表时间:
2022
期刊:
SN Computer Science
影响因子:
--
通讯作者:
Barbir, Abbie
Barbir, Abbie
中科院分区:
--
文献类型:
--
作者:
Wahab, Ahmed Anu;Hou, Daqing;Schuckers, Stephanie;Barbir, Abbie

文献摘要

参考文献

被引文献

相似文献

帐户恢复已成为移动的和Web应用程序中的一个普遍功能,它绕过了常规的基于用户名/密码的用户身份验证过程,因此已知其安全性较低且充满攻击。例如,为了触发帐户恢复过程,电子邮件或一次性密码(OTP)被发送到用户的注册电子邮件和/或电话。这假设只有真正的用户才能访问电子邮件/电话,但情况并非总是如此。为了进一步提高帐户恢复机制的安全性,除了验证用户输入的信息和其他凭证外,我们还提出了一种使用Rekes动力学的恢复方法。我们使用两个新的测试器来评估性能,第一个测试器包含从44名参与者的台式计算机上收集的超过500,000个测试器,而第二个测试器包含从39名参与者的触摸屏移动的手机上收集的327,000个测试器。这两个数据集都要求参与者填写多个字段的帐户恢复表格。对于每个数据集,我们评估了五种评分算法在各个领域,特征级融合和加权评分融合上的性能。我们还应用了一类分类,一种机器学习方法,并比较了结果。对于桌面数据集,我们实现了单个字段的最佳等错误率(EER)为5.47%,五个字段的特征级融合为0%,七个字段的加权评分融合为0%。对于触摸-移动的数据集,我们实现了最好的EER为10.25%的个人领域,4.97%的特征级融合的四个领域和2.26%的加权评分融合的七个领域。我们的研究结果表明,应用的动态是非常有前途的,以进一步确保帐户恢复机制在桌面和移动的平台。
Account recovery has become a prevalent feature across mobile and web applications that circumvents the regular username/password-based user authentication process, and thus is known to be less secure and fraught with attacks. For example, to trigger the account recovery process, an email or one-time password (OTP) is sent to the user’s registration email and/or phone. This assumes that only the genuine user has access to the email/phone which is not always the case. To further improve the security of the account recovery mechanism, beyond validating the information and other credentials typed by the user, we propose a recovery method with the use of keystrokes dynamics. We evaluated performances using two new keystroke datasets—the first contains over 500,000 keystrokes collected on a desktop computer from 44 participants, while the second 327,000 keystrokes on a touchscreen mobile phone from 39 participants. Both datasets require the participants to fill out an account recovery form of multiple fields. For each dataset, we evaluated the performance of five scoring algorithms on individual fields, feature-level fusion and weighted-score fusion. We also applied one-class classification, a machine learning approach and compared results. For the desktop dataset, we achieved the best equal error rate (EER) of 5.47% for individual fields, 0% for feature-level fusion of five fields, and 0% for weighted-score fusion of seven fields. For the touch-mobile dataset, we achieved the best EER of 10.25% for individual fields, 4.97% for feature-level fusion of four fields and 2.26% for weighted-score fusion of seven fields. Our results show that the application of keystroke dynamics is highly promising to further secure the account recovery mechanism on both desktop and mobile platforms.
DOI: 10.1007/978-0-387-35973-1_733
发表时间: 2008
期刊: --
影响因子: --
作者:
Shashi Shekhar;Hui Xiong
通讯作者: Shashi Shekhar;Hui Xiong
DOI: 10.1109/issre.2006.25
发表时间: 2006
期刊: 2006 17th International Symposium on Software Reliability Engineering
影响因子: --
作者:
Nick Bartlow;B. Cukic
通讯作者: B. Cukic
数据大小对自由文本击键认证性能的影响
DOI: --
发表时间: 2015
期刊: International Conference on Identity, Security and Behavior Analysis
影响因子: --
作者:
Jiaju Huang;Daqing Hou;S. Schuckers;Zhenhao Hou
通讯作者: Zhenhao Hou
使用固定文本通过击键动态进行用户身份验证
DOI: 10.1109/icbake.2009.42
发表时间: 2009
期刊: 2009 International Conference on Biometrics and Kansei Engineering
影响因子: --
作者:
M. Rybnik;P. Panasiuk;K. Saeed
通讯作者: K. Saeed
用于生物识别的击键动力学
DOI: 10.1007/978-3-540-71629-7_48
发表时间: 2007
期刊: J. Inf. Secur. Appl.
影响因子: --
作者:
M. Choraś;P. Mroczkowski
通讯作者: P. Mroczkowski