DocumentCode :
3003424
Title :
GUI Usage Analysis for Masquerade Detection
Author :
Imsand, Eric S. ; Hamilton, John A., Jr.
Author_Institution :
Auburn Univ., Auburn
fYear :
2007
fDate :
20-22 June 2007
Firstpage :
270
Lastpage :
276
Abstract :
This paper investigates a new method for detecting masquerade attacks. A masquerade attack is a form of attack wherein the attacker uses someone else´s identity or one system assumes the identity of another system. One extremely simple and dangerous form of a masquerade attack occurs when an attacker begins using an unattended and unlocked computer. In this paper, we present a new method for detecting this type of masquerade attack, based on the notion of how the current user interacts with the graphical user interface. This method does not use mouse movements or keystroke dynamics, rather profiles how the user manipulates the windows, icons, menus, and pointers that comprise a graphical user interface. In order to evaluate the performance of our method, we conducted some empirical studies in a real operational environment. While our results show some variations in performance, our method was able to detect up to 95% of simulated masquerade attacks with no false alarms. Furthermore, our method shows potential for use in real-time systems, requiring less data than other GUI interaction-based masquerade detection techniques while using a much simpler classification engine.
Keywords :
graphical user interfaces; security of data; GUI usage analysis; graphical user interface; masquerade attack; masquerade detection; Conferences; Engines; Graphical user interfaces; Information analysis; Intrusion detection; Manipulator dynamics; Mice; Operating systems; Real time systems; Tellurium; GUI usage; intrusion detection; masquerade detection; profiling;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Assurance and Security Workshop, 2007. IAW '07. IEEE SMC
Conference_Location :
West Point, NY
Print_ISBN :
1-4244-1304-4
Electronic_ISBN :
1-4244-1304-4
Type :
conf
DOI :
10.1109/IAW.2007.381943
Filename :
4267571
Link To Document :
بازگشت