【24h】

When Kids' Toys Breach Mobile Phone Security

机译:当孩子们的玩具违反手机安全

获取原文

摘要

Touch-based verification - the use of touch gestures (e.g., swiping, zooming, etc.) to authenticate users of touch screen devices - has recently been widely evaluated for its potential to serve as a second layer of defense to the PIN lock mechanism. In all performance evaluations of touch-based authentication systems however, researchers have assumed naive (zero-effort) forgeries in which the attacker makes no effort to mimic a given gesture pattern. In this paper we demonstrate that a simple "Lego" robot driven by input gleaned from general population swiping statistics can generate forgeries that achieve alarmingly high penetration rates against touch-based authentication systems. Using the best classification algorithms in touch-based authentication, we rigorously explore the effect of the attack, finding that it increases the Equal Error Rates of the classifiers by between 339% and 1004% depending on parameters such as the failure-to-enroll threshold and the type of touch stroke generated by the robot. The paper calls into question the zero-effort impostor testing approach used to benchmark the performance of touch-based authentication systems.
机译:基于触摸的验证 - 使用触摸手势(例如,滑动,缩放等)来验证触摸屏设备的用户 - 最近被广泛评估其作为针对PIN锁定机制的第二层防御的潜力。然而,在基于触摸的身份验证系统的所有性能评估中,研究人员已经假定了攻击者不努力模仿给定的手势模式的天真(零筹备)伪造。在本文中,我们展示了由一般人群刷统计信息引入的输入驱动的简单“乐高”机器人可以生成对基于触摸的身份验证系统实现令人惊出的渗透率的伪造者。使用最佳分类算法在基于触摸的身份验证中,我们严格探讨了攻击的效果,发现它会根据失败阈值等参数提高分类器的相同误差率在339%和1004%之间以及机器人产生的触摸行程类型。该文件调用了用于基于触摸的身份验证系统的性能的零努力冒号测试方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号