• DocumentCode
    182003
  • Title

    Continuous and Non-intrusive Reauthentication of Web Sessions Based on Mouse Dynamics

  • Author

    Medvet, Eric ; Bartoli, Alberto ; Boem, Francesca ; Tarlao, Fabiano

  • Author_Institution
    Dept. of Eng. & Archit., Univ. of Trieste, Trieste, Italy
  • fYear
    2014
  • fDate
    8-12 Sept. 2014
  • Firstpage
    166
  • Lastpage
    171
  • Abstract
    We propose a system for continuous reauthentication of Web users based on the observed mouse dynamics. Key feature of our proposal is that no specific software needs to be installed on client machines, which allows to easily integrate continuous reauthentication capabilities into the existing infrastructure of large organizations. We assess our proposal with real data from 24 users, collected during normal working activity for several working days. We obtain accuracy in the order of 97%, which is aligned with earlier proposals requiring instrumentation of client workstations for intercepting all mouse activity-quite a strong requirement for large organizations. Our proposal may constitute an effective layer for a defense-in-depth strategy in several key scenarios: Web applications hosted in the cloud, where users authenticate with standard mechanisms, organizations which allow local users to access external Web applications, and enterprise applications hosted in local servers or private cloud facilities.
  • Keywords
    authorisation; cloud computing; mouse controllers (computers); online front-ends; transport protocols; Web applications; Web users; client machines; client workstations; continuous nonintrusive Web session reauthentication capabilities; data collection; defense-in-depth strategy; enterprise applications; external Web application access; large-organization infrastructure; local servers; local users; mouse activity; mouse dynamics; normal working activity; private cloud facilities; standard mechanisms; user authentication; working days; Accuracy; Browsers; Mice; Organizations; Training data; Trajectory; Vectors; behavioral biometric; defense-in-depth;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Availability, Reliability and Security (ARES), 2014 Ninth International Conference on
  • Conference_Location
    Fribourg
  • Type

    conf

  • DOI
    10.1109/ARES.2014.29
  • Filename
    6980278