Cybersecurity Threats Based on Machine Learning-Based Offensive Technique for Password Authentication

被引:10
|
作者
Lee, Kyungroul [1 ]
Yim, Kangbin [2 ]
机构
[1] Soonchunhyang Univ, R&BD Ctr Secur & Safety Ind SSI, Asan 31538, South Korea
[2] Soonchunhyang Univ, Dept Informat Secur Engn, Asan 31538, South Korea
来源
APPLIED SCIENCES-BASEL | 2020年 / 10卷 / 04期
基金
新加坡国家研究基金会;
关键词
vulnerability analysis; password authentication; machine learning; user authentication;
D O I
10.3390/app10041286
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Due to the emergence of online society, a representative user authentication method that is password authentication has been a key topic. However, in this authentication method, various attack techniques have emerged to steal passwords input from the keyboard, hence, the keyboard data does not ensure security. To detect and prevent such an attack, a keyboard data protection technique using random keyboard data generation has been presented. This technique protects keyboard data by generating dummy keyboard data while the attacker obtains the keyboard data. In this study, we demonstrate the feasibility of keyboard data exposure under the keyboard data protection technique. To prove the proposed attack technique, we gathered all the dummy keyboard data generated by the defense tool, and the real keyboard data input by the user, and evaluated the cybersecurity threat of keyboard data based on the machine learning-based offensive technique. We verified that an adversary obtains the keyboard data with 96.2% accuracy even if the attack technique that makes it impossible to attack keyboard data exposure is used. Namely, the proposed method in this study obviously differentiates the keyboard data input by the user from dummy keyboard data. Therefore, the contributions of this paper are that we derived and verified a new security threat and a new vulnerability of password authentication. Furthermore, a new cybersecurity threat derived from this study will have advantages over the security assessment of password authentication and all types of authentication technology and application services input from the keyboard.
引用
下载
收藏
页数:16
相关论文
共 50 条
  • [1] Machine learning-based identification of cybersecurity threats affecting autonomous vehicle systems
    Onur, Furkan
    Gonen, Serkan
    Bariskan, Mehmet Ali
    Kubat, Cemallettin
    Tunay, Mustafa
    Yilmaz, Ercan Nurcan
    COMPUTERS & INDUSTRIAL ENGINEERING, 2024, 190
  • [2] Offensive Security of Keyboard Data Using Machine Learning for Password Authentication in IoT
    Lee, Kyungroul
    Lee, Jaehyuk
    Choi, Chang
    Yim, Kangbin
    IEEE ACCESS, 2021, 9 : 10925 - 10939
  • [3] Machine Learning-Based Cybersecurity Framework for IoT Devices
    Arabelli, Rajeshwarrao
    Buradkar, Mrunalini
    Lakshmaji, Kotla
    Dube, Anand Prakash
    Shiba, Mary C.
    Geetha, B. T.
    2024 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATION AND APPLIED INFORMATICS, ACCAI 2024, 2024,
  • [4] Design Guidelines for Machine Learning-based Cybersecurity in Internet of Things
    Boukerche, Azzedine
    Coutinho, Rodolfo W. L.
    IEEE NETWORK, 2021, 35 (01): : 393 - 399
  • [5] KeyNet: Enhancing Cybersecurity with Deep Learning-Based LSTM on Keystroke Dynamics for Authentication
    Soni, Jayesh
    Prabakar, Nagarajan
    INTELLIGENT HUMAN COMPUTER INTERACTION, IHCI 2021, 2022, 13184 : 761 - 771
  • [6] Machine Learning based Predictive Modelling of Cybersecurity Threats Utilising Behavioural Data
    Tin, Ting Tin
    Xin, Khiew Jie
    Aitizaz, Ali
    Tiung, Lee Kuok
    Keat, Teoh Chong
    Sarwar, Hasan
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (09) : 832 - 840
  • [7] Cybersecurity Risk and Audit Pricing-A Machine Learning-Based Analysis
    Jiang, Wanying
    JOURNAL OF INFORMATION SYSTEMS, 2024, 38 (01) : 91 - 117
  • [8] Enhancing graphical password authentication system with deep learning-based arabic digit recognition
    Rasheed A.F.
    Zarkoosh M.
    Elia F.R.
    International Journal of Information Technology, 2024, 16 (3) : 1419 - 1427
  • [9] SecRiskAI: a Machine Learning-Based Approach for Cybersecurity Risk Prediction in Businesses
    Franco, Muriel F.
    Sula, Erion
    Huertas, Alberto
    Scheid, Eder J.
    Granville, Lisandro Z.
    Stiller, Burkhard
    2022 IEEE 24TH CONFERENCE ON BUSINESS INFORMATICS (CBI 2022), VOL 1, 2022, : 1 - 10
  • [10] A machine learning-based physical layer authentication with phase impairments
    Ezzati Khatab, Zahra
    Mohammadi, Abbas
    Pourahmadi, Vahid
    Kuhestani, Ali
    Physical Communication, 2025, 68