Якісно кероване злиття контекстного та поведінкового скорингу для Risk-Based автентифікації
Вантажиться...
Файли
Дата
Автори
Назва журналу
Номер ISSN
Назва тому
Анотація
The article considers improving the efficiency of risk-based authentication during system login by combining two data sources: contextual features of the login attempt and behavioral biometric features generated based on the dynamics of keystrokes. It is shown that traditional approaches to combining contextual and behavioral scoring often do not take into account the quality of the behavioral sample, although it is it that significantly affects the reliability of the final decision. This is especially important for the practical application of RBA, even a slight shift in the risk assessment can lead either to unreasonably complicating the login for a legitimate user or to reducing the system&039;s ability to timely detect suspicious access attempts. Autofill fields, short passwords, event skipping, differences between input devices, changing keyboard layouts, browser features, and other factors can reduce the reliability of the behavioral channel and increase the frequency of false positives. In this regard, an approach is proposed in which the contribution of behavioral features to the final risk assessment is determined taking into account the quality of the received sample. A formal model of merging contextual and behavioral risk assessments has been developed, as well as an algorithm for setting decision thresholds for the modes of allowing access, additional verification, and denial of access. Experimental verification was performed on synthetic data and the open CMU Keystroke Dynamics Benchmark set. Comparison with basic fusion schemes showed that taking into account the quality of the sample allows for more adaptive use of the behavioral channel depending on the degree of its informativeness. The results obtained showed that the proposed approach allows for reducing the number of unnecessary additional checks without deteriorating the controlled level of security, and in conditions of low quality of behavioral data provides an even more tangible gain. The proposed solution is focused on increasing the stability of authentication without excessively increasing the load on the user. This confirms the feasibility of explicitly considering the quality of the behavioral pattern when building risk-based authentication systems and configuring their decision-making rules.
Опис
УДК
Тип документа
Мова
ISSN
Бібліографічний опис
Курніцький Д. П. Якісно кероване злиття контекстного та поведінкового скорингу для Risk-Based автентифікації // Вісник Вінницького політехнічного інституту. 2026. № 3. С. 61-69. URI: https://visnyk.vntu.edu.ua/index.php/visnyk/article/view/3515.
Схвалення
Рецензія
Доповнено
Цитується в
Список використаної літератури (24)
- ISO/IEC 29794-1:2016, Information technology – Biometric sample quality - Part 1: Framework. Geneva: International Organization for Standardization, 2016. [Electronic resource]. Available: https://www.iso.org/standard/66632.html.
- C. Guo, G. Pleiss, Y. Sun, and K. Q. Weinberger, “On Calibration of Modern Neural Networks,” in Proceedings of the 34th International Conference on Machine Learning, Proceedings of Machine Learning Research, vol. 70, 2017, pp. 1321-1330. [Electronic resource]. Available: http:// proceedings.mlr.press/v70/guo17a.html.
- X. Tong, Y. Feng, and J. J. Li, “Neyman-Pearson classification algorithms and NP receiver operating characteristics,” Science Advances, vol. 4, no. 2, Art. pp. 1659, 2018. https://doi.org/10.1126/sciadv.aao1659.
- H. Khan, U. Hengartner, and D. Vogel, “Mimicry Attacks on Smartphone Keystroke Authentication,” ACM Transactions on Privacy and Security, vol. 23, no. 1, Art. 2, pp. 1-34, 2020. https://doi.org/10.1145/3372420.
- K. S. Killourhy, and R. A. Maxion, “Keystroke Dynamics - Benchmark Data Set.” [Online]. Carnegie Mellon University, 2009. [Electronic resource]. Available: https://www.cs.cmu.edu/~keystroke/.
- I. Traore, I. Woungang, M. S. Obaidat, Y. Nakkabi, and I. Lai, “Combining Mouse and Keystroke Dynamics Biometrics for Risk-Based Authentication in Web Environments,” in 2012 Fourth International Conference on Digital Home, Guangzhou, 2012, pp. 138-145. https://doi.org/10.1109/ICDH.2012.59.
- J. Solano, L. D. Camacho, A. Correa, C. Deiro, J. Vargas, and M. Ochoa, “Risk-Based Static Authentication in Web Ap-plications with Behavioral Biometrics and Session Context Analytics,” in Applied Cryptography and Network Security Work-shops: ACNS 2019 Satellite Workshops, SiMLA, Cloud S&P, AIBlock, and AIoTS, J. Zhou et al., Eds. Bogota, Colombia, 2019, vol. 11605, pp. 3-23. https://doi.org/10.1007/978-3-030-29729-9_1.
- F. Monrose, and A. D. Rubin, “Keystroke dynamics as a biometric for authentication,” Future Generation Computer Sys-tems, vol. 16, no. 4, pp. 351-359, 2000. https://doi.org/10.1016/S0167-739X(99)00059-X.
- K. S. Killourhy, and R. A. Maxion, “Comparing Anomaly-Detection Algorithms for Keystroke Dynamics,” in 2009 IEEE/IFIP International Conference on Dependable Systems & Networks, 2009, pp. 125-134. https://doi.org/10.1109/DSN.2009.5270346.
- R. Giot, C. Rosenberger, and B. Dorizzi, “Hybrid Template Update System for Unimodal Biometric Systems,” in 2012 IEEE Fifth International Conference on Biometrics: Theory, Applications and Systems, 2012, pp. 1-7. https://doi.org/10.1109/BTAS.2012.6374551.