Show simple item record

dc.contributor.authorКурніцький, Д. П.uk
dc.contributor.authorKurnitskiy, D. P.en
dc.date.accessioned2026-08-20T09:56:17Z
dc.date.available2026-08-20T09:56:17Z
dc.date.issued2026
dc.identifier.citationКурніцький Д. П. Якісно кероване злиття контекстного та поведінкового скорингу для Risk-Based автентифікації // Вісник Вінницького політехнічного інституту. 2026. № 3. С. 61-69. URI: https://visnyk.vntu.edu.ua/index.php/visnyk/article/view/3515.uk
dc.identifier.issn1997-9274
dc.identifier.urihttps://ir.lib.vntu.edu.ua//handle/123456789/52343
dc.description.abstractThe article considers improving the efficiency of risk-based authentication during system login by combining two data sources: contextual features of the login attempt and behavioral biometric features generated based on the dynamics of keystrokes. It is shown that traditional approaches to combining contextual and behavioral scoring often do not take into account the quality of the behavioral sample, although it is it that significantly affects the reliability of the final decision. This is especially important for the practical application of RBA, even a slight shift in the risk assessment can lead either to unreasonably complicating the login for a legitimate user or to reducing the system&039;s ability to timely detect suspicious access attempts. Autofill fields, short passwords, event skipping, differences between input devices, changing keyboard layouts, browser features, and other factors can reduce the reliability of the behavioral channel and increase the frequency of false positives. In this regard, an approach is proposed in which the contribution of behavioral features to the final risk assessment is determined taking into account the quality of the received sample. A formal model of merging contextual and behavioral risk assessments has been developed, as well as an algorithm for setting decision thresholds for the modes of allowing access, additional verification, and denial of access. Experimental verification was performed on synthetic data and the open CMU Keystroke Dynamics Benchmark set. Comparison with basic fusion schemes showed that taking into account the quality of the sample allows for more adaptive use of the behavioral channel depending on the degree of its informativeness. The results obtained showed that the proposed approach allows for reducing the number of unnecessary additional checks without deteriorating the controlled level of security, and in conditions of low quality of behavioral data provides an even more tangible gain. The proposed solution is focused on increasing the stability of authentication without excessively increasing the load on the user. This confirms the feasibility of explicitly considering the quality of the behavioral pattern when building risk-based authentication systems and configuring their decision-making rules.en
dc.description.abstractРозглянуто підвищення ефективності автентифікації на основі ризику під час входу в систему шляхом поєднання двох джерел даних: контекстних ознак спроби входу та поведінкових біометричних ознак, сформованих на основі динаміки натискань клавіш. Показано, що традиційні підходи до об’єднання контекстного та поведінкового скорингу часто не враховують якість поведінкового зразка, хоча саме вона істотно впливає на надійність підсумкового рішення. Це особливо важливо для практичного застосування RBA, де навіть незначне зміщення оцінки ризику може призвести або до необґрунтованого ускладнення входу для легітимного користувача, або до зниження здатності системи своєчасно виявляти підозрілі спроби доступу. Автозаповнення полів, короткі паролі, пропуски подій, відмінності між пристроями введення, зміна клавіатурної розкладки, особливості браузера та інші чинники можуть знижувати достовірність поведінкового каналу й підвищувати частоту хибних спрацювань. У зв’язку з цим запропоновано підхід, у якому внесок поведінкових ознак у фінальну оцінку ризику визначається з урахуванням якості отриманого зразка. Розроблено формальну модель злиття контекстної та поведінкової оцінок ризику, а також алгоритм налаштування порогів прийняття рішень для режимів дозволу входу, додаткової перевірки та відмови в доступі. Експериментальну перевірку виконано на синтетичних даних і відкритому наборі CMU Keystroke Dynamics Benchmark. Порівняння з базовими схемами злиття показало, що врахування якості зразка дає змогу адаптивніше використовувати поведінковий канал залежно від ступеня його інформативності. Отримані результати засвідчили, що запропонований підхід дає змогу зменшити кількість зайвих додаткових перевірок без погіршення контрольованого рівня безпеки, а в умовах низької якості поведінкових даних забезпечує ще відчутніший виграш. Запропоноване рішення орієнтоване на підвищення стійкості автентифікації без надмірного зростання навантаження на користувача. Це підтверджує доцільність явного врахування якості поведінкового зразка під час побудови систем автентифікації на основі ризику та налаштування їхніх правил ухвалення рішень.uk
dc.language.isouk_UAuk_UA
dc.publisherВНТУuk
dc.relation.ispartofВісник Вінницького політехнічного інституту. № 3 : 61-69.uk
dc.relation.urihttps://visnyk.vntu.edu.ua/index.php/visnyk/article/view/3515
dc.subjectавтентифікація на основі ризикуuk
dc.subjectконтекстні ознаки входуuk
dc.subjectповедінкові біометричні ознакиuk
dc.subjectдинаміка натискань клавішuk
dc.subjectоцінювання якості поведінкового зразкаuk
dc.subjectзлиття оцінок ризикуuk
dc.subjectпорогове прийняття рішеньuk
dc.subjectдодаткова перевіркаuk
dc.subjectконтроль доступуuk
dc.subjectінформаційна безпекаuk
dc.subjectrisk-based authenticationen
dc.subjectcontextual login featuresen
dc.subjectbehavioral biometric featuresen
dc.subjectkeystroke dynamicuk
dc.subjectbehavioral pattern quality assessmenten
dc.subjectrisk assessment fusionen
dc.subjectthreshold decision-makingen
dc.subjectadditional verificationen
dc.subjectaccess controlen
dc.subjectinformation securityen
dc.titleЯкісно кероване злиття контекстного та поведінкового скорингу для Risk-Based автентифікаціїuk
dc.title.alternativeQuality-Driven Fusion of Contextual and Behavioral Scoring for Risk-Based Authenticationen
dc.typeArticle, professional native edition
dc.typeArticle
dc.identifier.udc004.421
dc.relation.referencesISO/IEC 29794-1:2016, Information technology – Biometric sample quality - Part 1: Framework. Geneva: International Organization for Standardization, 2016. [Electronic resource]. Available: https://www.iso.org/standard/66632.html.en
dc.relation.referencesC. Guo, G. Pleiss, Y. Sun, and K. Q. Weinberger, “On Calibration of Modern Neural Networks,” in Proceedings of the 34th International Conference on Machine Learning, Proceedings of Machine Learning Research, vol. 70, 2017, pp. 1321-1330. [Electronic resource]. Available: http:// proceedings.mlr.press/v70/guo17a.html.en
dc.relation.referencesX. Tong, Y. Feng, and J. J. Li, “Neyman-Pearson classification algorithms and NP receiver operating characteristics,” Science Advances, vol. 4, no. 2, Art. pp. 1659, 2018. https://doi.org/10.1126/sciadv.aao1659.en
dc.relation.referencesH. Khan, U. Hengartner, and D. Vogel, “Mimicry Attacks on Smartphone Keystroke Authentication,” ACM Transactions on Privacy and Security, vol. 23, no. 1, Art. 2, pp. 1-34, 2020. https://doi.org/10.1145/3372420.en
dc.relation.referencesK. S. Killourhy, and R. A. Maxion, “Keystroke Dynamics - Benchmark Data Set.” [Online]. Carnegie Mellon University, 2009. [Electronic resource]. Available: https://www.cs.cmu.edu/~keystroke/.en
dc.relation.referencesI. Traore, I. Woungang, M. S. Obaidat, Y. Nakkabi, and I. Lai, “Combining Mouse and Keystroke Dynamics Biometrics for Risk-Based Authentication in Web Environments,” in 2012 Fourth International Conference on Digital Home, Guangzhou, 2012, pp. 138-145. https://doi.org/10.1109/ICDH.2012.59.en
dc.relation.referencesJ. Solano, L. D. Camacho, A. Correa, C. Deiro, J. Vargas, and M. Ochoa, “Risk-Based Static Authentication in Web Ap-plications with Behavioral Biometrics and Session Context Analytics,” in Applied Cryptography and Network Security Work-shops: ACNS 2019 Satellite Workshops, SiMLA, Cloud S&P, AIBlock, and AIoTS, J. Zhou et al., Eds. Bogota, Colombia, 2019, vol. 11605, pp. 3-23. https://doi.org/10.1007/978-3-030-29729-9_1.en
dc.relation.referencesF. Monrose, and A. D. Rubin, “Keystroke dynamics as a biometric for authentication,” Future Generation Computer Sys-tems, vol. 16, no. 4, pp. 351-359, 2000. https://doi.org/10.1016/S0167-739X(99)00059-X.en
dc.relation.referencesK. S. Killourhy, and R. A. Maxion, “Comparing Anomaly-Detection Algorithms for Keystroke Dynamics,” in 2009 IEEE/IFIP International Conference on Dependable Systems & Networks, 2009, pp. 125-134. https://doi.org/10.1109/DSN.2009.5270346.en
dc.relation.referencesR. Giot, C. Rosenberger, and B. Dorizzi, “Hybrid Template Update System for Unimodal Biometric Systems,” in 2012 IEEE Fifth International Conference on Biometrics: Theory, Applications and Systems, 2012, pp. 1-7. https://doi.org/10.1109/BTAS.2012.6374551.en
dc.relation.referencesJ. C. Platt, “Probabilistic Outputs for Support Vector Machines and Comparisons to Regularized Likelihood Methods,” in Advances in Large Margin Classifiers. Cambridge, MA: MIT Press, 1999, pp. 61-74. [Electronic resource]. Available: https://www.microsoft.com/en-us/research/publication/probabilistic-outputs-for-support-vector-machines-and-comparisons-to-regularized-likelihood-methods/.en
dc.relation.referencesY. Geifman, and R. El-Yaniv, “Selective Classification for Deep Neural Networks,” CoRR, Abs/1705.08500, 2017. [Electronic resource]. Available: https://arxiv.org/abs/1705.08500.en
dc.relation.referencesT. M. Mitchell, “Generative and Discriminative Classifiers: Naive Bayes and Logistic Regression.” Draft chapter for the second edition of Machine Learning. Carnegie Mellon University, 2020. [Electronic resource]. Available: https://www.cs.cmu.edu/~tom/mlbook/NBayesLogReg.pdf.en
dc.relation.referencesR. A. Jacobs, M. I. Jordan, S. J. Nowlan, and G. E. Hinton, “Adaptive Mixtures of Local Experts,” Neural Computation, vol. 3, pp. 79-87, 1991. https://doi.org/10.1162/neco.1991.3.1.79.en
dc.relation.referencesB. Efron, and R. J. Tibshirani, An Introduction to the Bootstrap. Boca Raton, FL: Chapman & Hall, 1994, 456 p. [Electronic re-source]. Available: https:// www.routledge.com/An-Introduction-to -the-Bootstrap/Efron-Tibshirani/p/book/9780412042317.en
dc.relation.referencesC. J. Clopper, and E. S. Pearson, “The Use of Confidence or Fiducial Limits Illustrated in the Case of the Binomial,” Bi-ometrika, vol. 26, no. 4, pp. 404-413, 1934. https://doi.org/10.1093/biomet/26.4.404.en
dc.relation.referencesA. N. Angelopoulos, S. Bates, A. Fisch, L. Lei, and T. Schuster, “Conformal Risk Control,” CoRR, Abs/2208.02814, 2022. https://doi.org/10.48550/arXiv.2208.02814.en
dc.relation.referencesP. H. Pisani, R. Giot, A. C. P. L. F. Carvalho, and A. C. Lorena, “Enhanced template update: Application to keystroke dynamics,” Computers & Security, vol. 60, pp. 134-153, 2016. https://doi.org/10.1016/j.cose.2016.04.004.en
dc.relation.referencesR. Giot, M. El-Abed, and C. Rosenberger, “GREYC Keystroke: A Benchmark for Keystroke Dynamics Biometric Sys-tems,” in 2009 IEEE 3rd International Conference on Biometrics: Theory, Applications, and Systems, Washington, DC, 2009, pp. 1-6. https://doi.org/10.1109/BTAS.2009.5339051.en
dc.relation.referencesB. Bhana, and S. Flowerday, “Passphrase and keystroke dynamics authentication: Usable security,” Computers & Secu-rity, vol. 96, Art. 101925, 2020. https://doi.org/10.1016/j.cose.2020.101925.en
dc.relation.referencesJ. Kim, and P. Kang, “Freely typed keystroke dynamics-based user authentication for mobile devices based on heteroge-neous features,” Pattern Recognition, vol. 108, Art. 107556, 2020. https://doi.org/10.1016/j.patcog.2020.107556.en
dc.relation.referencesY. Liang, S. Samtani, B. Guo, and Z. Yu, “Behavioral biometrics for continuous authentication in the internet-of-things era: an artificial intelligence perspective,” IEEE Internet of Things Journal, vol. 7, no. 9, pp. 9128-9143, 2020. https://doi.org/10.1109/JIOT.2020.3004077.en
dc.relation.referencesL. S. Dasu, M. Dhamija, G. Dishitha, A. Vivekanandan, and V. Sarasvathi, “Defending Against Identity Threats Using Risk-Based Authentication,” Cybernetics and Information Technologies, vol. 23, no. 2, pp. 105-123, 2023. https://doi.org/10.2478/cait-2023-0016.en
dc.relation.referencesY. Yang, B. Guo, Y. Liang, K. Zhao, and Z. Yu, “Cross-device free-text keystroke dynamics authentication using federated learning,” Personal and Ubiquitous Computing, vol. 28, no. 3-4, pp. 491-505, 2024. https://doi.org/10.1007/s00779-024-01832-6.en
dc.identifier.doihttps://doi.org/10.31649/1997-9266-2026-186-3-61-69
dc.identifier.orcidhttps://orcid.org/0009-0000-3190-9514


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record