Biometric techniques are often used as an extra security factor in authenticating human users. Numerous biometrics have been proposed and evaluated, each with its own set of benefits and pitfalls. Static biometrics (such as fingerprints) are geared for discrete operation, to identify users, which typically involves some user burden. Meanwhile, behavioral biometrics (such as keystroke dynamics) are well suited for continuous, and sometimes more unobtrusive, operation. One important application domain for biometrics is deauthentication, a means of quickly detecting absence of a previously authenticated user and immediately terminating that user's active secure sessions. Deauthentication is crucial for mitigating so called Lunchtime Attacks, whereby an insider adversary takes over (before any inactivity timeout kicks in) authenticated state of a careless user who walks away from her computer. Motivated primarily by the need for an unobtrusive and continuous biometric to support effective deauthentication, we introduce PoPa, a new hybrid biometric based on a human user's seated posture pattern. PoPa captures a unique combination of physiological and behavioral traits. We describe a low cost fully functioning prototype that involves an office chair instrumented with 16 tiny pressure sensors. We also explore (via user experiments) how PoPa can be used in a typical workplace to provide continuous authentication (and deauthentication) of users. We experimentally assess viability of PoPa in terms of uniqueness by collecting and evaluating posture patterns of a cohort of users. Results show that PoPa exhibits very low false positive, and even lower false negative, rates. In particular, users can be identified with, on average, 91.0% accuracy. Finally, we compare pros and cons of PoPa with those of several prominent biometric based deauthentication techniques.
翻译:生物测定技术往往被用作认证人类用户的附加安全因素。 许多生物测定技术都已经提出和评估,每个生物测定技术都有其自身的好处和缺陷。 静态生物测定技术(如指纹)被调整为离散操作, 以识别用户, 这通常包含一些用户负担。 同时, 行为生物测定技术( 如键盘动态) 也非常适合连续操作, 有时更不受侵扰的操作。 生物测定技术的一个重要应用领域是解析, 这是一种快速发现缺乏先前认证的用户并立即终止用户活跃的安全会话的手段。 光度测定对于减少所谓的午餐时间袭击至关重要, 从而让一个内幕对手取代( 任何活动超时速动作), 从而识别用户, 从而识别出一个不留意和连续的生物测定, 支持有效解析, 我们引入了一种基于人类用户正坐状态的新的混合生物测定方法。 POPA 将一个特殊的生理和行为特征组合, 将一个典型的生理和行为特征用户的典型模型进行我们使用一个低成本的实验 。