Title :
Effects of User Habituation in Keystroke Dynamics on Password Security Policy
Author :
Syed, Zahid ; Banerjee, Sean ; Cheng, Qi ; Cukic, Bojan
Author_Institution :
Lane Dept. of Comput. Sci. & Electr. Eng., West Virginia Univ., Morgantown, WV, USA
Abstract :
Access control systems rely on a variety of methods for authenticating legitimate users and preventing malicious ones from accessing the system. The most commonly used system is a simple username and password approach. This technology has been the de-facto standard for remote authentication applications. A username-password based system assumes that only the genuine users know their own credentials. However, breaching this type of system has become a common occurrence in today´s age of social networks and modern computational devices. Once broken, the system will accept every authentication trial using compromised credentials until the breach is detected. In this paper, we explore certain aspects of utilizing keystroke dynamics in username-password based systems. We show that as users get habituated to typing their credentials, there is a significant reduction in the variance of the keystroke patterns. This trend is more pronounced for long and complex passwords as opposed to short dictionary based passwords. We also study the time window necessary to perceive habituation in user typing patterns. Furthermore, we show that habituation plays a key role in classification of genuine login attempts by reducing the equal error rate (EER) over time. Finally, we explore an authentication scheme that employs the security of complex passwords and keystroke dynamics.
Keywords :
authorisation; social networking (online); access control system; complex password security; computational devices; de-facto standard; dictionary based password; equal error rate; genuine login classification; keystroke dynamics; keystroke pattern; legitimate user authentication scheme; password security policy; remote authentication application; social network; user habituation; username-password based system; Authentication; Buildings; Delay; Presses; Servers; Training; Keystroke Dynamics; Soft biometrics; User Authentication;
Conference_Titel :
High-Assurance Systems Engineering (HASE), 2011 IEEE 13th International Symposium on
Conference_Location :
Boca Raton, FL
Print_ISBN :
978-1-4673-0107-7
DOI :
10.1109/HASE.2011.16