Online risk-based authentication using behavioral biometrics

被引:17
作者
Traore, Issa [1 ]
Woungang, Isaac [2 ]
Obaidat, Mohammad S. [3 ]
Nakkabi, Youssef [1 ]
Lai, Iris [1 ]
机构
[1] Univ Victoria, Dept Elect & Comp Engn, Victoria, BC V8W 3P6, Canada
[2] Ryerson Univ, Dept Comp Sci, Toronto, ON M5B 2K3, Canada
[3] Monmouth Univ, Dept Comp Sci & Software Engn, West Long Branch, NJ 07764 USA
关键词
Risk-based authentication; Network security; Mouse dynamics; Keystroke dynamics biometric technology; Bayesian network model; Digital home network; Infrastructure technology; USER AUTHENTICATION;
D O I
10.1007/s11042-013-1518-5
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In digital home networks, it is expected that independent smart devices communicate and cooperate with each other, without the knowledge of the fundamental communication technology, on the basis of a distributed operating system paradigm. In such context, securing the access rights to some objects such as data, apparatus, and contents, is still a challenge. This paper introduces a risk-based authentication technique based on behavioral biometrics as solution approach to tackle this challenge. Risk-based authentication is an increasingly popular component in the security architecture deployed by many organizations to mitigate online identity fraud. Risk-based authentication uses contextual and historical information extracted from online communications to build a risk profile for the user that can be used accordingly to make authentication and authorization decisions. Existing risk-based authentication systems rely on basic web communication information such as the source IP address or the velocity of transactions performed by a specific account, or originating from a certain IP address. Such information can easily be spoofed, and as such, put in question the robustness and reliability of the proposed systems. In this paper, we propose a new online risk-based authentication system that provides more robust user identity information by combining mouse dynamics and keystroke dynamics biometrics in a multimodal framework. We propose a Bayesian network model for analyzing free keystrokes and free mouse movements involved in web sessions. Experimental evaluation of our proposed model with 24 participants yields an Equal Error Rate of 8.21 %. This is very encouraging considering that we are dealing with free text and free mouse movements, and the fact that many web sessions tend to be very short.
引用
收藏
页码:575 / 605
页数:31
相关论文
共 31 条
[1]   A new biometric technology based on mouse dynamics [J].
Ahmed, Ahmed Awad E. ;
Traore, Issa .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2007, 4 (03) :165-179
[2]  
Aksari Y, 2009, 2009 24TH INTERNATIONAL SYMPOSIUM ON COMPUTER AND INFORMATION SCIENCES, P569
[3]  
[Anonymous], 2007, P 2 ACM S INFORM COM
[4]  
Bergadano F., 2002, ACM Transactions on Information and Systems Security, V5, P367, DOI 10.1145/581271.581272
[5]  
Bouckaert RemcoR., 2004, BAYESIAN NETWORK CLA
[6]  
Bours P, 2009, P 5 INT C INT INF HI
[7]  
Cheng P.-C., 2007, RC24190 IBM
[8]  
Diep Nguyen Ngoc, 2007, Proceedings of the 2007 International Conference on Security & Management. SAM 2007, P406
[9]  
DIMMOCK N, 2005, LNCS, V3477
[10]  
DOWLAND P, 2001, P 8 IFIP ANN WORK C