Revisiting the Security of Biometric Authentication Systems Against Statistical Attacks

被引:2
|
作者
Habib, Sohail [1 ]
Khan, Hassan [1 ]
Hamilton-Wright, Andrew [1 ]
Hengartner, Urs [2 ]
机构
[1] Univ Guelph, Sch Comp Sci, Guelph, ON, Canada
[2] Univ Waterloo, Cheriton Sch Comp Sci, Waterloo, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
Statistical attacks; behavioral biometrics; voice authentication; gait authentication; keystroke authentication; GAIT RECOGNITION; TECHNOLOGY; FRAMEWORK; NICHE;
D O I
10.1145/3571743
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The uniqueness of behavioral biometrics (e.g., voice or keystroke patterns) has been challenged by recent works. Statistical attacks have been proposed that infer general population statistics and target behavioral biometrics against a particular victim. We show that despite their success, these approaches require several attempts for successful attacks against different biometrics due to the different nature of overlap in users' behavior for these biometrics. Furthermore, no mechanism has been proposed to date that detects statistical attacks. In this work, we propose a new hypervolumes-based statistical attack and show that unlike existing methods, it (1) is successful against a variety of biometrics, (2) is successful against more users, and (3) requires fewest attempts for successful attacks. More specifically, across five diverse biometrics, for the first attempt, on average our attack is 18 percentage points more successful than the second best (37% vs. 19%). Similarly, for the fifth attack attempt, on average our attack is 18 percentage points more successful than the second best (67% vs. 49%). We propose and evaluate a mechanism that can detect the more devastating statistical attacks. False rejects in biometric systems are common, and by distinguishing statistical attacks from false rejects, our defense improves usability and security. The evaluation of the proposed detection mechanism shows its ability to detect on average 94% of the tested statistical attacks with an average probability of 3% to detect false rejects as a statistical attack. Given the serious threat posed by statistical attacks to biometrics that are used today (e.g., voice), our work highlights the need for defending against these attacks.
引用
收藏
页数:30
相关论文
共 50 条
  • [1] Security evaluation of biometric authentication systems under real spoofing attacks
    Biggio, B.
    Akhtar, Z.
    Fumera, G.
    Marcialis, G. L.
    Roli, F.
    IET BIOMETRICS, 2012, 1 (01) : 11 - 24
  • [2] Security Analysis of Multimodal Biometric Systems against Spoof Attacks
    Akhtar, Zahid
    Kale, Sandeep
    ADVANCES IN COMPUTING AND COMMUNICATIONS, PT 2, 2011, 191 : 604 - +
  • [3] On usability (and security) of biometric authentication systems
    Matyas, V
    SECURITY AND PRIVACY IN ADVANCED NETWORKING TECHNOLOGIES, 2004, 193 : 178 - 188
  • [4] Provoking Security: Spoofing Attacks against Crypto-Biometric Systems
    Toli, Christina-Angeliki
    Preneel, Bart
    2015 WORLD CONGRESS ON INTERNET SECURITY (WORLDCIS), 2015, : 67 - 72
  • [5] Biometric Authentication Systems: Security Concerns and Solutions
    Bhartiya, Namrata
    Jangid, Namrata
    Jannu, Sheetal
    2018 3RD INTERNATIONAL CONFERENCE FOR CONVERGENCE IN TECHNOLOGY (I2CT), 2018,
  • [6] New Security Definitions for Biometric Authentication with Template Protection: Toward covering more threats against authentication systems
    Isshiki, Toshiyuki
    Araki, Toshinori
    Mori, Kengo
    Obana, Satoshi
    Ohki, Tetsushi
    Sakamoto, Shizuo
    PROCEEDINGS OF THE 12TH INTERNATIONAL CONFERENCE OF THE BIOMETRICS SPECIAL INTEREST GROUP (BIOSIG 2013), 2013,
  • [7] Implementing templates security in remote biometric authentication systems
    Khan, Muhammad Khurram
    Zhang, Jiashu
    2006 INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY, PTS 1 AND 2, PROCEEDINGS, 2006, : 1396 - 1400
  • [8] Basic Study on Presentation Attacks against Biometric Authentication using Photoplethysmogram
    Hinatsu, Shun
    Suzuki, Daisuke
    Ishizuka, Hiroki
    Ikeda, Sei
    Oshiro, Osamu
    ADVANCED BIOMEDICAL ENGINEERING, 2021, 10 : 101 - 112
  • [9] Person authentication using speech as a biometric against play back attacks
    Revathi, A.
    Jeyalakshmi, C.
    Thenmozhi, K.
    MULTIMEDIA TOOLS AND APPLICATIONS, 2019, 78 (02) : 1569 - 1582
  • [10] Person authentication using speech as a biometric against play back attacks
    A. Revathi
    C. Jeyalakshmi
    K. Thenmozhi
    Multimedia Tools and Applications, 2019, 78 : 1569 - 1582