首页> 外文期刊>IEEE transactions on information forensics and security >Snoop-Forge-Replay Attacks on Continuous Verification With Keystrokes
【24h】

Snoop-Forge-Replay Attacks on Continuous Verification With Keystrokes

机译:通过按键连续验证的Snoop-Forge-Replay攻击

获取原文
获取原文并翻译 | 示例

摘要

We present a new attack called the snoop-forge-replay attack on keystroke-based continuous verification systems. The snoop-forge-replay is a sample-level forgery attack and is not specific to any particular keystroke-based continuous verification method or system. It can be launched with easily available keyloggers and APIs for keystroke synthesis. Our results from 2640 experiments show that: 1) the snoop-forge-replay attacks achieve alarmingly high error rates compared to zero-effort impostor attacks, which have been the de facto standard for evaluating keystroke-based continuous verification systems; 2) four state-of-the-art verification methods, three types of keystroke latencies, and 11 matching-pair settings (-a key parameter in continuous verification with keystrokes) that we examined in this paper were susceptible to the attack; 3) the attack is effective even when as low as 20 to 100 keystrokes were snooped to create forgeries. In light of our results, we question the security offered by current keystroke-based continuous verification systems. Additionally, in our experiments, we harnessed virtualization technology to generate thousands of keystroke forgeries within a short time span. We point out that virtualization setup such as the one used in our experiments can also be exploited by an attacker to scale and speedup the attack.
机译:我们在基于击键的连续验证系统上提出了一种新的攻击,称为“窥探伪造重放攻击”。探听伪造重放是样本级别的伪造攻击,并不特定于任何特定的基于击键的连续验证方法或系统。可以使用易于使用的按键记录器和用于按键合成的API来启动它。我们从2640个实验中得出的结果表明:1)与零努力冒名顶替者攻击相比,探听伪造重放攻击实现了惊人的高错误率,而零努力冒名顶替者攻击已经成为评估基于击键的连续验证系统的事实上的标准; 2)我们在本文中研究了四种最新的验证方法,三种类型的按键等待时间以及11种匹配对设置(-使用击键连续验证中的关键参数)容易受到攻击; 3)即使窃听了20到100次击键以创建伪造品,攻击也仍然有效。根据我们的结果,我们质疑当前基于击键的连续验证系统提供的安全性。此外,在我们的实验中,我们利用虚拟化技术在短时间内生成了数千个按键伪造。我们指出,攻击者还可以利用虚拟化设置(例如实验中使用的那种设置)来扩展和加速攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号