Cargando…

A Framework for Continuous Authentication Based on Touch Dynamics Biometrics for Mobile Banking Applications

As smart devices have become commonly used to access internet banking applications, these devices constitute appealing targets for fraudsters. Impersonation attacks are an essential concern for internet banking providers. Therefore, user authentication countermeasures based on biometrics, whether ph...

Descripción completa

Detalles Bibliográficos
Autores principales: Estrela, Priscila Morais Argôlo Bonfim, Albuquerque, Robson de Oliveira, Amaral, Dino Macedo, Giozza, William Ferreira, Júnior, Rafael Timóteo de Sousa
Formato: Online Artículo Texto
Lenguaje:English
Publicado: MDPI 2021
Materias:
Acceso en línea:https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8234896/
https://www.ncbi.nlm.nih.gov/pubmed/34205344
http://dx.doi.org/10.3390/s21124212
_version_ 1783714189634699264
author Estrela, Priscila Morais Argôlo Bonfim
Albuquerque, Robson de Oliveira
Amaral, Dino Macedo
Giozza, William Ferreira
Júnior, Rafael Timóteo de Sousa
author_facet Estrela, Priscila Morais Argôlo Bonfim
Albuquerque, Robson de Oliveira
Amaral, Dino Macedo
Giozza, William Ferreira
Júnior, Rafael Timóteo de Sousa
author_sort Estrela, Priscila Morais Argôlo Bonfim
collection PubMed
description As smart devices have become commonly used to access internet banking applications, these devices constitute appealing targets for fraudsters. Impersonation attacks are an essential concern for internet banking providers. Therefore, user authentication countermeasures based on biometrics, whether physiological or behavioral, have been developed, including those based on touch dynamics biometrics. These measures take into account the unique behavior of a person when interacting with touchscreen devices, thus hindering identitification fraud because it is hard to impersonate natural user behaviors. Behavioral biometric measures also balance security and usability because they are important for human interfaces, thus requiring a measurement process that may be transparent to the user. This paper proposes an improvement to Biotouch, a supervised Machine Learning-based framework for continuous user authentication. The contributions of the proposal comprise the utilization of multiple scopes to create more resilient reasoning models and their respective datasets for the improved Biotouch framework. Another contribution highlighted is the testing of these models to evaluate the imposter False Acceptance Error (FAR). This proposal also improves the flow of data and computation within the improved framework. An evaluation of the multiple scope model proposed provides results between 90.68% and 97.05% for the harmonic mean between recall and precision (F1 Score). The percentages of unduly authenticated imposters and errors of legitimate user rejection (Equal Error Rate (EER)) are between 9.85% and 1.88% for static verification, login, user dynamics, and post-login. These results indicate the feasibility of the continuous multiple-scope authentication framework proposed as an effective layer of security for banking applications, eventually operating jointly with conventional measures such as password-based authentication.
format Online
Article
Text
id pubmed-8234896
institution National Center for Biotechnology Information
language English
publishDate 2021
publisher MDPI
record_format MEDLINE/PubMed
spelling pubmed-82348962021-06-27 A Framework for Continuous Authentication Based on Touch Dynamics Biometrics for Mobile Banking Applications Estrela, Priscila Morais Argôlo Bonfim Albuquerque, Robson de Oliveira Amaral, Dino Macedo Giozza, William Ferreira Júnior, Rafael Timóteo de Sousa Sensors (Basel) Article As smart devices have become commonly used to access internet banking applications, these devices constitute appealing targets for fraudsters. Impersonation attacks are an essential concern for internet banking providers. Therefore, user authentication countermeasures based on biometrics, whether physiological or behavioral, have been developed, including those based on touch dynamics biometrics. These measures take into account the unique behavior of a person when interacting with touchscreen devices, thus hindering identitification fraud because it is hard to impersonate natural user behaviors. Behavioral biometric measures also balance security and usability because they are important for human interfaces, thus requiring a measurement process that may be transparent to the user. This paper proposes an improvement to Biotouch, a supervised Machine Learning-based framework for continuous user authentication. The contributions of the proposal comprise the utilization of multiple scopes to create more resilient reasoning models and their respective datasets for the improved Biotouch framework. Another contribution highlighted is the testing of these models to evaluate the imposter False Acceptance Error (FAR). This proposal also improves the flow of data and computation within the improved framework. An evaluation of the multiple scope model proposed provides results between 90.68% and 97.05% for the harmonic mean between recall and precision (F1 Score). The percentages of unduly authenticated imposters and errors of legitimate user rejection (Equal Error Rate (EER)) are between 9.85% and 1.88% for static verification, login, user dynamics, and post-login. These results indicate the feasibility of the continuous multiple-scope authentication framework proposed as an effective layer of security for banking applications, eventually operating jointly with conventional measures such as password-based authentication. MDPI 2021-06-19 /pmc/articles/PMC8234896/ /pubmed/34205344 http://dx.doi.org/10.3390/s21124212 Text en © 2021 by the authors. https://creativecommons.org/licenses/by/4.0/Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
spellingShingle Article
Estrela, Priscila Morais Argôlo Bonfim
Albuquerque, Robson de Oliveira
Amaral, Dino Macedo
Giozza, William Ferreira
Júnior, Rafael Timóteo de Sousa
A Framework for Continuous Authentication Based on Touch Dynamics Biometrics for Mobile Banking Applications
title A Framework for Continuous Authentication Based on Touch Dynamics Biometrics for Mobile Banking Applications
title_full A Framework for Continuous Authentication Based on Touch Dynamics Biometrics for Mobile Banking Applications
title_fullStr A Framework for Continuous Authentication Based on Touch Dynamics Biometrics for Mobile Banking Applications
title_full_unstemmed A Framework for Continuous Authentication Based on Touch Dynamics Biometrics for Mobile Banking Applications
title_short A Framework for Continuous Authentication Based on Touch Dynamics Biometrics for Mobile Banking Applications
title_sort framework for continuous authentication based on touch dynamics biometrics for mobile banking applications
topic Article
url https://www.ncbi.nlm.nih.gov/pmc/articles/PMC8234896/
https://www.ncbi.nlm.nih.gov/pubmed/34205344
http://dx.doi.org/10.3390/s21124212
work_keys_str_mv AT estrelapriscilamoraisargolobonfim aframeworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT albuquerquerobsondeoliveira aframeworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT amaraldinomacedo aframeworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT giozzawilliamferreira aframeworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT juniorrafaeltimoteodesousa aframeworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT estrelapriscilamoraisargolobonfim frameworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT albuquerquerobsondeoliveira frameworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT amaraldinomacedo frameworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT giozzawilliamferreira frameworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications
AT juniorrafaeltimoteodesousa frameworkforcontinuousauthenticationbasedontouchdynamicsbiometricsformobilebankingapplications