Xác thực PIN bằng mô hình phát hiện bất thường đa mô hình trong động học gõ phím trên thiết bị di động - Luận văn Thạc sĩ của Ghofran Mahmood Khalaf
Không có nội dung để mô tả.
Middle East University
Luan An
Luận văn thạc sĩ
Năm xuất bản
Số trang
72
Thời gian đọc
11 phút
Lượt xem
1
Lượt tải
0
Phí lưu trữ
40 Point
Tổng quan nhanh
- Chủ đề:
- Xác thực PIN di động: Phát hiện bất thường đa mô hình
- Số trang:
- 72 trang
- Trường:
- Middle East University
- Chuyên ngành:
- Computer Science
- Tác giả:
- Ghofran Mahmood Khalaf
- Năm:
- 2019
Tóm tắt nội dung luận án
I.Xác thực PIN di động Phát hiện bất thường đa mô hình
1.1. Thách thức xác thực PIN trên thiết bị di động
Xác thực PIN truyền thống đang đối mặt với nhiều rủi ro bảo mật. Các phương pháp dựa trên kiến thức như PIN dễ bị lộ do tấn công vai kề hoặc phần mềm độc hại. Nhu cầu về một giải pháp bảo mật PIN hiệu quả và đáng tin cậy ngày càng cao. Xác thực di động đặc biệt đòi hỏi sự cân bằng giữa tính tiện lợi và mức độ an toàn. Việc bảo vệ dữ liệu nhạy cảm trên smartphone là ưu tiên hàng đầu. Công nghệ hiện tại cần được nâng cấp để chống lại các mối đe dọa mới.
1.2. Giới thiệu sinh trắc học hành vi để xác thực PIN
Sinh trắc học hành vi cung cấp một lớp bảo mật bổ sung mạnh mẽ. Phương pháp này phân tích các mẫu hành vi độc đáo của người dùng khi tương tác với thiết bị. Thay vì chỉ dựa vào "cái gì bạn biết", nó tập trung vào "cách bạn làm". Điều này bao gồm động lực gõ phím và các đặc điểm cảm ứng khác. Việc sử dụng sinh trắc học hành vi giúp nâng cao đáng kể bảo mật thiết bị di động. Nó tạo ra một hồ sơ cá nhân hóa cho mỗi người dùng, khó bị giả mạo.
1.3. Khái niệm phát hiện bất thường đa mô hình
Phát hiện bất thường là kỹ thuật xác định các hoạt động hoặc hành vi không điển hình. Khi áp dụng cho xác thực PIN, nó tìm kiếm sự sai lệch so với mẫu gõ phím thông thường của người dùng hợp lệ. Mô hình đa mô hình kết hợp nhiều thuật toán và phương pháp phát hiện khác nhau. Việc này cải thiện độ chính xác và khả năng chống lại các loại tấn công đa dạng. Sự tổng hợp từ nhiều nguồn dữ liệu và kỹ thuật học máy tạo ra một hệ thống xác thực mạnh mẽ hơn, giảm thiểu lỗi.
II.Cải thiện bảo mật thiết bị di động với động lực gõ phím
2.1. Cơ chế hoạt động của động lực gõ phím
Động lực gõ phím là một kỹ thuật sinh trắc học hành vi phân tích cách người dùng nhập liệu. Nó đo lường các yếu tố tinh tế như thời gian giữ phím, thời gian giữa các phím và áp lực khi chạm. Phân tích này bao gồm tốc độ gõ, nhịp điệu và các đặc điểm cảm ứng khác. Mỗi cá nhân sở hữu một phong cách gõ phím riêng biệt, gần như một "chữ ký" số. Các đặc điểm này đủ độc đáo để phân biệt người dùng hợp pháp với kẻ tấn công.
2.2. Trích xuất đặc trưng từ dữ liệu gõ phím
Dữ liệu thô thu được từ quá trình gõ phím trên màn hình cảm ứng cần được chuyển đổi. Các đặc trưng quan trọng được trích xuất, bao gồm thời gian gõ, thời gian tạm dừng giữa các phím. Ngoài ra, các đặc trưng cảm ứng như khu vực ngón tay chạm và áp lực cũng được thu thập. Việc này tạo ra một tập dữ liệu giàu thông tin cho phân tích sâu hơn. Các đặc trưng này là nền tảng cho việc nhận dạng và phân loại hành vi người dùng.
2.3. Lợi ích cho xác thực PIN liên tục
Động lực gõ phím hỗ trợ khả năng xác thực liên tục. Hệ thống không chỉ xác thực ban đầu mà còn liên tục kiểm tra hành vi người dùng trong suốt phiên làm việc. Điều này giúp phát hiện bất thường ngay lập tức nếu có sự thay đổi đáng ngờ trong cách nhập liệu. Khả năng xác thực liên tục củng cố bảo mật chủ động trên thiết bị di động. Nó cung cấp một lớp phòng thủ động, thay vì chỉ là một kiểm tra tĩnh một lần duy nhất. Điều này tăng cường đáng kể an ninh tổng thể cho người dùng.
III.Phương pháp xác thực đa mô hình Học máy trong bảo mật
3.1. Các mô hình phát hiện bất thường đơn lẻ
Các mô hình phát hiện bất thường đơn lẻ sử dụng một thuật toán hoặc phương pháp cụ thể. Mỗi mô hình phân tích hành vi người dùng theo một khía cạnh riêng. Chúng có thể dựa trên các ngưỡng thống kê đơn giản hoặc các thuật toán học máy cơ bản. Mặc dù hiệu quả ở một mức độ nào đó, khả năng phát hiện của chúng có thể bị giới hạn. Các mô hình đơn lẻ có thể dễ dàng bị qua mặt bởi các kiểu tấn công tinh vi hơn. Chúng thường chỉ hiệu quả với các kiểu bất thường đã biết hoặc rõ ràng.
3.2. Ưu điểm của mô hình phát hiện đa mô hình
Mô hình phát hiện đa mô hình khắc phục nhược điểm của các mô hình đơn lẻ. Nó kết hợp nhiều thuật toán và phương pháp khác nhau một cách thông minh. Điều này tăng cường đáng kể khả năng chống lại các cuộc tấn công phức tạp và chưa từng thấy. Bằng cách tổng hợp thông tin từ nhiều nguồn, hệ thống có cái nhìn toàn diện hơn về hành vi. Khả năng phát hiện gian lận di động được cải thiện đáng kể. Sự kết hợp này mang lại độ tin cậy và hiệu quả cao hơn trong việc nhận diện các mối đe dọa.
3.3. Quy trình tính toán điểm và xác định kết quả PIN
Trong một hệ thống đa mô hình, mỗi mô hình con sẽ tạo ra một điểm số bất thường. Những điểm số này phản ánh mức độ sai lệch so với hồ sơ hành vi hợp lệ. Các điểm số sau đó được tổng hợp hoặc kết hợp thông qua một thuật toán tổng hợp. Một ngưỡng quyết định được áp dụng để phân loại hành vi. Hệ thống xác định liệu PIN được nhập là hợp lệ hay có dấu hiệu bất thường. Quy trình này đảm bảo xác thực PIN di động hiệu quả và chính xác, tăng cường bảo mật.
IV.Phân tích hành vi người dùng Dữ liệu và kết quả thực nghiệm
4.1. Thu thập dữ liệu và lựa chọn tập đặc trưng
Việc thu thập dữ liệu gõ phím là bước thiết yếu để xây dựng mô hình. Dữ liệu được thu thập từ nhiều người dùng trên thiết bị di động thực tế. Các tập đặc trưng chính và phụ được xác định cẩn thận. Những đặc trưng này bao gồm các thông số về thời gian gõ, tốc độ nhập, và áp lực ngón tay. Quá trình thu thập dữ liệu kỹ lưỡng đảm bảo chất lượng và tính đại diện. Đây là nền tảng vững chắc cho việc đào tạo và kiểm thử mô hình phát hiện bất thường.
4.2. Hệ thống PIN Dynamics đề xuất
Một hệ thống mới mang tên "PIN Dynamics" đã được đề xuất và phát triển. Hệ thống này được thiết kế để xác thực PIN dựa trên động lực gõ phím của người dùng. Nó tích hợp các mô hình phát hiện bất thường đa mô hình để đạt hiệu quả cao nhất. Giao diện người dùng thân thiện hỗ trợ quá trình thu thập dữ liệu và đăng ký. Hệ thống này ứng dụng sâu rộng học máy trong bảo mật để phân tích hành vi. Mục tiêu là cung cấp một giải pháp xác thực PIN di động mạnh mẽ và tiện lợi.
4.3. Đánh giá hiệu suất và so sánh kết quả
Các thử nghiệm thực nghiệm rộng rãi đã được tiến hành để đánh giá hiệu suất của hệ thống. Tỷ lệ lỗi cân bằng (EER) được sử dụng làm thước đo chính để đánh giá độ chính xác. EER giúp cân bằng giữa tỷ lệ chấp nhận sai và tỷ lệ từ chối sai. Kết quả của hệ thống được so sánh với các bộ dữ liệu và phương pháp hiện có. Hệ thống đã chứng minh khả năng phát hiện bất thường hiệu quả. Các phát hiện này củng cố niềm tin vào tính khả thi của xác thực đa mô hình.
V.Tương lai bảo mật chủ động Xác thực liên tục di động
5.1. Tầm quan trọng của xác thực PIN nâng cao
Trong bối cảnh các mối đe dọa an ninh mạng ngày càng tinh vi, nhu cầu bảo mật thiết bị di động không ngừng tăng lên. Các giải pháp xác thực mạnh mẽ hơn là điều cần thiết để bảo vệ thông tin cá nhân và tài sản số. Xác thực PIN di động tiên tiến, như hệ thống đề xuất, mang lại một lớp bảo vệ vững chắc. Nó giúp người dùng an tâm hơn khi thực hiện các giao dịch hoặc truy cập dữ liệu nhạy cảm. Đây là một bước tiến quan trọng trong việc tăng cường an toàn số.
5.2. Hướng phát triển cho công nghệ sinh trắc học hành vi
Công nghệ sinh trắc học hành vi có nhiều tiềm năng phát triển trong tương lai. Có thể tích hợp thêm các đặc trưng sinh trắc học hành vi khác, ngoài động lực gõ phím. Ví dụ bao gồm cách cầm nắm thiết bị, cách vuốt màn hình. Mở rộng ứng dụng sang các loại thiết bị khác như đồng hồ thông minh hoặc thiết bị IoT. Việc cải thiện liên tục các thuật toán học máy trong bảo mật sẽ nâng cao khả năng phát hiện bất thường. Nghiên cứu sâu hơn về phân tích hành vi người dùng sẽ dẫn đến các hệ thống thông minh hơn.
5.3. Tiềm năng ứng dụng rộng rãi
Công nghệ xác thực dựa trên phát hiện bất thường đa mô hình có tiềm năng ứng dụng rộng rãi. Từ giao dịch ngân hàng di động, thanh toán không tiếp xúc đến truy cập ứng dụng và dữ liệu nhạy cảm. Nó cung cấp một lớp bảo mật chủ động, liên tục giám sát hành vi người dùng. Khả năng phát hiện gian lận di động được củng cố đáng kể, giảm thiểu rủi ro. Xác thực liên tục là một bước tiến lớn, mang lại sự bảo vệ toàn diện hơn so với các phương pháp truyền thống.
Mục lục chi tiết luận án
Tải xuống file đầy đủ để xem toàn bộ nội dung
Tải đầy đủ (72 trang)Trích đoạn nội dung luận án
Tải xuống để đọc toàn bộCover Page PIN Authentication Using Multi-Model Anomaly Detection in Keystroke Dynamics on Mobile Devices التحقق من الرقم الشخصي باستخدام نموذج متعدد لكشف التباين في اسلوب الكتابة على المفاتيح على االجهزة المحمولة By Ghofran Mahmood Khalaf Supervisor Dr. Mudhafar Al-Jarrah A Thesis Submitted in Partial Fulfillment of the Requirements for the Master Degree in Computer Science Department of Computer Science Faculty of Information Technology Middle East University Jan. 2019 II Authorization III Thesis Committee Decision IV Acknowledgement (شيء بعد ٍ و ِم ْل َء ما ِشْئ َت ِمن،األرض ِ ِ ِملء السمو،) اللهم ربنا لك الحمد ات و ِم ْل َء َْ First and above all, I give special thanks, praise and glory to Almighty Allah for his mercy, and reconcile and for granting me knowledge, confidence, patience to pass this Master thesis successfully. I would like to express my profound thank to my thesis advisor.
Muthafar Al- Jarrah for suggesting this field of research work and continue working with full enthusiasm. I gratefully acknowledge his kindness, patience, encouragement, for the complete guidance throughout the thesis stages, and for the critical assistance in designing and proceeding the methodology of my research. In addition, I would like to express my deepest gratitude to all the respectable lecturers at the Faculty of Information Technology, Middle East University. I also appreciate the effort and time that the professors of the committee spend in reading and discussing the thesis.
The Researcher Ghofran Mahmood V بسم هللا الرحمن الرحيم ""وقل ربي زدني علما Dedication This thesis dedicated to my whole family; Especial thanks to my one and only my mother, who always proud of me and supported me in every step of my life, no words can describe what you have done for me, thank you for your endless love. My Father, who taught me to work hard for the things that I aspire to achieve. My Sisters and brother, who are one part of my life. My aunts, who support and love me.
My best friends, who always been there for me during difficult and stressful times, particularly, Renad Al-Manaseer. My friends Fatima and Russel, who support me with their precious words and love me, and I thank Allah for their presence in my life. My friends, who supported me with their nice words, who were the cause of my happiness during my last days at university, and who loved them and will stay in my heart. VI Table of Contents Title.
II Thesis Committee Decision. V Table of Contents. VI List of Abbreviations. VIII List of Tables.
IX List of Figures. XI Arabic Abstract. XII Chapter One .2 Background of the Study.4 Scope of Work.5 Limitations of the Research Work .6 Goal and Objectives .8 Significance of Work. 6 Background and Literature Review .6 Keystroke Dynamics Technology .7 Ensemble Models Concept .1 Simple Ensemble Techniques.2 Advanced Ensemble Techniques .9 Summary of Related Work.
23 Methodology and the Proposed Model .2 Outline of the Proposed Model .3 The Proposed Work .4 Anomaly Detector Models .1 Single Anomaly Detection Models .2 Multi-Model Anomaly Detectors .3 Template Calculation of the Single Anomaly Detectors .4 Score Calculation and Outcome of the Typed PIN .6 The Data Collection System. 34 Experimental Results and Discussion .2 Objectives of the Experimental Work .3 Feature Sets Selection .4 The Proposed (PIN Dynamics) System.5 Screen Shots of the Proposed (PIN Dynamics) System .6 EER Analysis Steps.7 Data Collection Using the Proposed (PIN Dynamics) System .8 Results and Discussion .9 Comparison with EER Results of the MOBIKEY data set. 48 Conclusion and Future Work .2 Suggestion for Future Work. 57 VIII List of Abbreviations Abbreviations Meaning AAD Average Absolute Deviation CSV Comma Separated Values EER Equal-Error-Rate FAR False-Acceptance-Rate FRR False-Rejection-Rate KSD Keystroke Dynamics MAD Median Absolute Deviation PIN Personal Identification Number STD Standard Deviation IX List of Tables Chapter No.
Contents Page No.1 Summary of the Review of Related Study 20 4.1 List of Primary and Secondary Feature Sets 35 4.2 EER Analysis Results Using Primary Features 43 4.3 EER Analysis Results Using Secondary Features 44 4.4 EER Analysis Results Using a Reduced Imposter Set 45 4.5 Summary of EER Results of the MOBKEY Data set 47 X List of Figures Chapter No. Contents Page No.3 Enter PIN Code Enrollment Screen 39 XI PIN Authentication Using Multi-Model Anomaly Detection in Keystroke Dynamics on Mobile Devices By: Ghofran Mahmood Khalaf Supervisor: Dr. Mudhafar Al-Jarrah Abstract The use of behavioral biometrics in user authentication has recently moved to new security application areas, one of which is verifying the Personal Identification Number (PIN). This thesis investigates the design of anomaly detectors and feature sets for PIN authentication on touch mobile devices.
The work involved a selection of raw data feature sets that are extracted from modern mobile devices, such as finger area, pressure, and timestamp. A set of primary and secondary authentication features have been formulated, which are calculated from the raw data features. The proposed anomaly detectors are based on the outlier concept, where an input PIN’s calculated feature element is classified as imposter value if it is outside an acceptable zone from a central value such as the mean or median of a set of training values. The Z-Score method is used as the distance function of the anomaly detectors, and three versions are investigated; the standard deviation-based Z-Score, the modified Z-Score which uses the Median-Absolute-Deviation (MAD) and the Average- Absolute-Deviation (AAD) Z-Score function.
Also, the three single models are combined into ensemble models. The proposed feature sets are implemented as a data collection system on a Nexus-9 Android tablet. Experimental work resulted in collecting a PIN dataset (PIN Dynamics) from 70 subjects, where the data included genuine and imposter PIN data. The raw data features data from the new dataset were converted to the proposed authentication primary and secondary features.
The authentication features dataset was analyzed by utilizing the three single anomaly detectors and the three ensemble anomaly detectors, using the Equal-Error-Rate (EER) metric. The results showed that the AAD Z-Score anomaly detector produced the lowest error rate among the single models, while the merged AAD and MAD ensemble model achieved the lowest overall error rate. The thesis ends with a conclusion and suggestion for future work. Keywords: PIN; Anomaly Detector; Z-Score; EER; MAD; AAD; Feature Set; Ensemble Model.يتم استخدام طريقة Z-Score كوظيفة المسافة للكشف عن الشذوذ ،ويتم التحقيق في ثالثة إصدارات؛ مقياس Z-Scoreالمعتمد على االنحراف المعياري ،المعدل Z-Scoreالذي يستخدم االنحراف المطلق ( )MADودالة Z-Score لالمتداد المطلق ( .نتج عن موضوعا ،حيث تضمنت ً العمل التجريبي جمع مجموعة بيانات ) PIN (PIN Dynamicsمن 07 البيانات بيانات PINحقيقية ونامية .)EERوأظهرت النتائج أن كاشف الشاذة AAD Z-Scoreأنتج أدنى معدل للخطأ بين النماذج المفردة ،في حين حقق نموذج AADو MADالمدمج أدنى معدل للخطأ الكلي . 1 Chapter One Introduction 1.1 Research Context This thesis deals with the problem of user authentication on mobile devices, using keystroke dynamics behavioral biometrics of the user on touch screens, through anomaly detection models and features to support the verification of Personal Identification Number (PIN) codes.2 Background of the Study The research explores different behavioral biometric approaches to increase the authentication security on mobile devices, using available sensor data on modern tablets and smartphones (mobile devices).
Several studies have addressed the issue of user authentication using the keystroke dynamics modality, based on various anomaly detection models and feature sets (Killourhy, 2012; Aljarrah2013; Al-Obaidi2016). Most of the reported experimental work utilized a common 12-character password that was proposed by Kilorhy and Maxion (2009), while Antal and Lehel Nemes (2016) considered alternative strong and easy passwords. The use of short passcodes such as the PIN code in security systems has been investigated due to the wide-spread utilization of 4-digit PIN codes in banks’ ATM and credit cards, on mobile devices, and in buildings access control systems. Problem Statement The problem addressed in this study is the strengthening of user authentication on mobile devices where an intruder has captured the PIN code.
The research investigates the use of the keystroke dynamics modality features on mobile devices, combined multi-model anomaly detection models, to improve the detection accuracy of the short 4-digit PIN code.4 Scope of Work The research proposes to examine anomaly detection models and features that can be utilized to enhance user authentication on touch / mobile devices, using a short numeric passcode, based on the keystroke dynamics approach. Alternative single models and ensemble models will be investigated, using alternative feature sets derived from PIN typing data.5 Limitations of the Research Work The main limitation of this research is that the proposed model and experimental work will be based on the Android platform. Further work will be needed for implementation on other mobile platforms such as IOS.6 Goal and Objectives The aim of this research is to improve the authentication of users on touch mobile devices using a short password approach, the 4-digit Personal Identification Number (PIN) and the keystroke dynamics approach. The following objectives are taken into consideration: 1.
Investigation of the set of biometric features that will be used in the user authentication process. Selection of alternative single anomaly detection models and model ensembles to enhance authentication. Implementation of the raw features data collection system as a tool on the Android operating system. Experimental work to collect the raw features data.
Evaluation of the proposed anomaly detection models and feature sets using the new datasets.7 Motivation The need for better authentication of users on technological systems such as mobile devices, banks ATM terminals, and buildings access control panels, continue to require higher dependability methods to prevent illegal access by impostors. Traditional PIN or password- based approaches have the limitation that secret codes can be elicited by various methods such as shoulder-surfing or video recording, therefore additional traits of a user are needed to be included in the authentication process.8 Significance of Work The expected significance of this work is in enhancing the security of mobile devices, and similar touch devices, by adopting new anomaly detection models and features, and utilizing available sensor data, without the need to add any special hardware. What are the single and multi-model anomaly detectors that will be used in the authentication process? 2. What are the new authentication features that will be used? 3.
Will increasing the number of biometric features result in better authentication? 4. Will combining several anomaly detectors as an ensemble result in better authentication? 5. What will be the error metrics that will be measured in the experimental study and what are the achieved error rates? 1.10 Thesis Organization This thesis is divided into five chapters: Chapter one: contains general concepts of this thesis which include the topic, background of the study, problem statement, scope of work, limitation of the proposed work, goal and objectives, motivation, the significance of work and questions to be answered. Chapter two: presents the literature review, concepts, and definitions which introduced the introduction, classification methods, biometric technologies, and related work.
Chapter three: presents the methodology and the proposed model, which introduced the methodology approach, the outline of the proposed model, methodology steps, features selection, the anomaly detector, the proposed system and error metrics. 5 Chapter four: presents experimental results and discussion, which introduced the introduction, objectives of the experimental work, EER analysis steps, feature sets selection, analysis of the (PIN Dynamics) dataset, the proposed system, data collection the proposed system and discussion of results. Chapter five: contains conclusions and future work. 6 Chapter Two Background and Literature Review 2.1 Background The last decades have witnessed an explosion of computing (i., mobile devices, the applications running on them, and the underlying infrastructure).
Mobile computing is a prime target of authentication fraud because the level of security in mobile devices is, in general, kept to the minimum not only by design but sometimes for the convenience of the users. While numerous protection schemes are available on these devices, many users view these protections as hindrances and tend to disable or bypass them.
Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ
Trích dẫn luận án này
Ghofran Mahmood Khalaf (2019). Xác thực PIN bằng phát hiện bất thường đa mô hình trên thiết bị di động [Luận án tiến sĩ, Middle East University]. LuanAn.net. https://luanan.net/cong-nghe-thong-tin/an-toan-thong-tin/xac-thuc-pin-bang-phat-hien-bat-thuong-da-mo-hinh-tren-thiet-bi-di-dong
Câu hỏi thường gặp
Luận án "Xác thực PIN bằng phát hiện bất thường đa mô hình trên thiết bị di động" nghiên cứu về vấn đề gì?
Không có nội dung để mô tả.
Luận án "Xác thực PIN bằng phát hiện bất thường đa mô hình trên thiết bị di động" được bảo vệ tại trường nào?
Luận án này được bảo vệ tại Middle East University. Năm bảo vệ: 2019.
Luận án "Xác thực PIN bằng phát hiện bất thường đa mô hình trên thiết bị di động" thuộc chuyên ngành gì?
Luận án "Xác thực PIN bằng phát hiện bất thường đa mô hình trên thiết bị di động" thuộc chuyên ngành Computer Science. Danh mục: An Toàn Thông Tin.
Luận án "Xác thực PIN bằng phát hiện bất thường đa mô hình trên thiết bị di động" có bao nhiêu trang?
Luận án "Xác thực PIN bằng phát hiện bất thường đa mô hình trên thiết bị di động" có 72 trang. Bạn có thể xem trước một phần tài liệu ngay trên trang web trước khi tải về.
Cách tải luận án "Xác thực PIN bằng phát hiện bất thường đa mô hình trên thiết bị di động" về máy như thế nào?
Để tải luận án về máy, bạn nhấn nút "Tải xuống ngay" trên trang này, sau đó hoàn tất thanh toán phí lưu trữ. File sẽ được tải xuống ngay sau khi thanh toán thành công. Hỗ trợ qua Zalo: 0559 297 239.