首页> 外文期刊>Computers & Security >Robustness of keystroke-dynamics based biometrics against synthetic forgeries
【24h】

Robustness of keystroke-dynamics based biometrics against synthetic forgeries

机译:基于击键动力学的生物识别技术对合成伪造的鲁棒性

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

Biometric systems including keystroke-dynamics based authentication have been well studied in the literature. The attack model in biometrics typically considers impersonation attempts launched by human imposters. However, this attack model is not adequate, as advanced attackers may utilize programs to forge data. In this paper, we consider the effects of synthetic forgery attacks in the context of biometric authentication systems. Our study is performed in a concrete keystroke-dynamic authentication system. The main focus of our work is evaluating the security of keystroke-dynamics authentication against synthetic forgery attacks. Our analysis is performed in a remote authentication framework called TUBA that we design and implement for monitoring a user's typing patterns. We evaluate the robustness of TUBA through experimental evaluation including two series of simulated bots. The keystroke sequences forged by the two bots are modeled using first-order Markov chains. Support vector machine is used for classification. Our results, based on 20 users' keystroke data, are reported. Our work shows that keystroke dynamics is robust against the two specific types of synthetic forgery attacks studied, where attacker draws statistical samples from a pool of available keystroke dataset other than the target. We also describe TUBA's use for detecting anomalous activities on remote hosts, and present its use in a specific cognition-based anomaly detection system. The use of TUBA provides high assurance on the information collected from the hosts and enables remote security diagnosis and monitoring.
机译:在文献中已经对包括基于击键动力学的认证的生物识别系统进行了充分的研究。生物识别技术中的攻击模型通常会考虑由冒名顶替者发起的假冒尝试。但是,此攻击模型并不足够,因为高级攻击者可能会利用程序来伪造数据。在本文中,我们考虑了生物识别系统中合成伪造攻击的影响。我们的研究是在一个具体的按键动态认证系统中进行的。我们工作的主要重点是评估击键动态身份验证对合成伪造攻击的安全性。我们的分析是在称为TUBA的远程身份验证框架中执行的,我们设计并实现了该框架以监视用户的键入模式。我们通过包括两个系列的模拟机器人在内的实验评估来评估TUBA的鲁棒性。这两个机器人伪造的击键序列是使用一阶马尔可夫链建模的。支持向量机用于分类。报告了基于20个用户的击键数据的结果。我们的工作表明,击键动力学对于研究的两种特定类型的合成伪造攻击具有鲁棒性,其中攻击者从目标以外的可用击键数据集中提取统计样本。我们还描述了TUBA在远程主机上检测异常活动的用途,并介绍了它在基于认知的特定异常检测系统中的用途。使用TUBA可以高度保证从主机收集的信息,并可以进行远程安全诊断和监视。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号