A User Study of Keystroke Dynamics as Second Factor in Web MFA

A. Wahab, Daqing Hou, S. Schuckers
{"title":"A User Study of Keystroke Dynamics as Second Factor in Web MFA","authors":"A. Wahab, Daqing Hou, S. Schuckers","doi":"10.1145/3577923.3583642","DOIUrl":null,"url":null,"abstract":"As account compromises and malicious online attacks are on the rise, multi-factor authentication (MFA) has been adopted to defend against these attacks. OTP and mobile push notification are just two examples of the popularly adopted MFA factors. Although MFA improve security, they also add additional steps or hardware to the authentication process, thus increasing the authentication time and introducing friction. On the other hand, keystroke dynamics-based authentication is believed to be a promising MFA for increasing security while reducing friction. While there have been several studies on the usability of other MFA factors, the usability of keystroke dynamics has not been studied. To this end, we have built a web authentication system with the standard features of signup, login and account recovery, and integrated keystroke dynamics as an additional factor. We then conducted a user study on the system where 20 participants completed tasks related to signup, login and account recovery. We have also evaluated a new approach for completing the user enrollment process, which reduces friction by naturally employing other alternative MFA factors (OTP in our study) when keystroke dynamics is not ready for use. Our study shows that while maintaining strong security (0% FPR), adding keystroke dynamics reduces authentication friction by avoiding 66.3% of OTP at login and 85.8% of OTP at account recovery, which in turn reduces the authentication time by 63.3% and 78.9% for login and account recovery respectively. Through an exit survey, all participants have rated the integration of keystroke dynamics with OTP to be more preferable to the conventional OTP-only authentication.","PeriodicalId":387479,"journal":{"name":"Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy","volume":"24 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-04-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3577923.3583642","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

As account compromises and malicious online attacks are on the rise, multi-factor authentication (MFA) has been adopted to defend against these attacks. OTP and mobile push notification are just two examples of the popularly adopted MFA factors. Although MFA improve security, they also add additional steps or hardware to the authentication process, thus increasing the authentication time and introducing friction. On the other hand, keystroke dynamics-based authentication is believed to be a promising MFA for increasing security while reducing friction. While there have been several studies on the usability of other MFA factors, the usability of keystroke dynamics has not been studied. To this end, we have built a web authentication system with the standard features of signup, login and account recovery, and integrated keystroke dynamics as an additional factor. We then conducted a user study on the system where 20 participants completed tasks related to signup, login and account recovery. We have also evaluated a new approach for completing the user enrollment process, which reduces friction by naturally employing other alternative MFA factors (OTP in our study) when keystroke dynamics is not ready for use. Our study shows that while maintaining strong security (0% FPR), adding keystroke dynamics reduces authentication friction by avoiding 66.3% of OTP at login and 85.8% of OTP at account recovery, which in turn reduces the authentication time by 63.3% and 78.9% for login and account recovery respectively. Through an exit survey, all participants have rated the integration of keystroke dynamics with OTP to be more preferable to the conventional OTP-only authentication.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
击键动力学作为Web MFA第二因素的用户研究
随着帐户泄露和恶意在线攻击的增加,多因素身份验证(multi-factor authentication, MFA)被用于防御这些攻击。OTP和手机推送通知只是被广泛采用的MFA因素的两个例子。尽管MFA提高了安全性,但它们也在身份验证过程中添加了额外的步骤或硬件,从而增加了身份验证时间并引入了摩擦。另一方面,基于击键动态的身份验证被认为是一种很有前途的MFA,可以在减少摩擦的同时提高安全性。虽然对其他MFA因素的可用性进行了一些研究,但对击键动力学的可用性尚未进行研究。为此,我们建立了一个具有注册、登录和帐户恢复标准功能的web认证系统,并集成了击键动力学作为附加因素。然后,我们对系统进行了用户研究,其中20名参与者完成了与注册,登录和帐户恢复相关的任务。我们还评估了一种完成用户注册过程的新方法,当击键动力学还没有准备好使用时,该方法通过自然地使用其他替代MFA因素(在我们的研究中是OTP)来减少摩擦。我们的研究表明,在保持强大的安全性(0% FPR)的同时,添加击键动力学可以通过避免登录时66.3%的OTP和帐户恢复时85.8%的OTP来减少认证摩擦,从而分别将登录和帐户恢复的认证时间减少63.3%和78.9%。通过退出调查,所有参与者都认为将击键动力学与OTP集成比传统的仅OTP身份验证更可取。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Tackling Credential Abuse Together Comparative Privacy Analysis of Mobile Browsers Confidential Execution of Deep Learning Inference at the Untrusted Edge with ARM TrustZone Local Methods for Privacy Protection and Impact on Fairness Role Models: Role-based Debloating for Web Applications
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1