• DocumentCode
    2789436
  • Title

    Effects of User Habituation in Keystroke Dynamics on Password Security Policy

  • Author

    Syed, Zahid ; Banerjee, Sean ; Cheng, Qi ; Cukic, Bojan

  • Author_Institution
    Lane Dept. of Comput. Sci. & Electr. Eng., West Virginia Univ., Morgantown, WV, USA
  • fYear
    2011
  • fDate
    10-12 Nov. 2011
  • Firstpage
    352
  • Lastpage
    359
  • Abstract
    Access control systems rely on a variety of methods for authenticating legitimate users and preventing malicious ones from accessing the system. The most commonly used system is a simple username and password approach. This technology has been the de-facto standard for remote authentication applications. A username-password based system assumes that only the genuine users know their own credentials. However, breaching this type of system has become a common occurrence in today´s age of social networks and modern computational devices. Once broken, the system will accept every authentication trial using compromised credentials until the breach is detected. In this paper, we explore certain aspects of utilizing keystroke dynamics in username-password based systems. We show that as users get habituated to typing their credentials, there is a significant reduction in the variance of the keystroke patterns. This trend is more pronounced for long and complex passwords as opposed to short dictionary based passwords. We also study the time window necessary to perceive habituation in user typing patterns. Furthermore, we show that habituation plays a key role in classification of genuine login attempts by reducing the equal error rate (EER) over time. Finally, we explore an authentication scheme that employs the security of complex passwords and keystroke dynamics.
  • Keywords
    authorisation; social networking (online); access control system; complex password security; computational devices; de-facto standard; dictionary based password; equal error rate; genuine login classification; keystroke dynamics; keystroke pattern; legitimate user authentication scheme; password security policy; remote authentication application; social network; user habituation; username-password based system; Authentication; Buildings; Delay; Presses; Servers; Training; Keystroke Dynamics; Soft biometrics; User Authentication;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    High-Assurance Systems Engineering (HASE), 2011 IEEE 13th International Symposium on
  • Conference_Location
    Boca Raton, FL
  • ISSN
    1530-2059
  • Print_ISBN
    978-1-4673-0107-7
  • Type

    conf

  • DOI
    10.1109/HASE.2011.16
  • Filename
    6113919