<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: multifactor]]></title>
    <link>http://securityratty.com/tag/multifactor</link>
    <description></description>
    <pubDate>Mon, 19 Feb 2007 14:00:11 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[That thing you do keystroke dynamics]]></title>
      <link>http://securityratty.com/article/1cfd62e1befeb8656845611171bf8bf1</link>
      <guid>http://securityratty.com/article/1cfd62e1befeb8656845611171bf8bf1</guid>
      <description><![CDATA[For years, security professionals have known and been saying that passwords themselves are inadequate thus the need for two-factor (or stronger) authentication. However, multifactor authentication...]]></description>
      <content:encoded><![CDATA[<p>For years, security professionals have known and been saying that passwords themselves are inadequate &#8212; thus the need for two-factor (or stronger) authentication.  However, multifactor authentication implementations are typically known to be costly (e.g. issuing tokens or biometric readers).  Further, many companies report user push-back: some end-users reject or express disdain for biometric authentication.</p>
<p>So, this begs the question: &#8220;Is there a multifactor authentication method that is transparent to end-users?&#8221;  And the answer is, &#8220;yes.&#8221;  The technology is referred to as &#8220;keystroke dynamics,&#8221; and it extends the authentication paradigm a bit.  That is, you usually hear about authentication factors such as:</p>
<ul>
<li>Something you <em>know</em> (e.g. Password)</li>
<li>Something you <em>have</em> (e.g. token)</li>
<li>Something you <em>are</em> (e.g. biometric)</li>
</ul>
<p><em>Keystroke dynamics, as well as signature and speech dynamics, add to that list &#8220;<strong>Something you do</strong>.&#8221;</em></p>
<p>Keystroke dynamics systems check the specific characteristics of how someone enters his/her password (i.e. speed, pauses).  So, in effect, keystroke dynamics systems are keyloggers who have turned from the Dark Side. <img src='http://securityrenaissance.com/wordpress/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>In theory, the use of such systems allows users to simply continue entering a single password – the way they do now. Yet, because individual and unique characteristics are being measured, many of the traditional weaknesses associated with passwords can be overcome.  For example, normal “problem areas” such as password sharing and shoulder surfing may be mitigated because other parties cannot mimic the “dwell time” (length of time that the key is pressed) and “flight time” (speed between individual keystrokes) dynamics of the actual user.</p>
<p>Though I&#8217;ve not yet done any tests with this technology, I do see it touted as an affordable, reliable alternative to biometrics.</p>
<p>Links for further reading/research:</p>
<p><strong><u>General info:</u></strong></p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Keystroke_dynamics">http://en.wikipedia.org/wiki/Keystroke_dynamics</a></li>
<li><u><a href="http://articles.techrepublic.com.com/5100-1009-6150761.html">http://articles.techrepublic.com.com/5100-1009-6150761.html</a></u></li>
<li><a href="http://avirubin.com/fgcs.pdf">http://avirubin.com/fgcs.pdf</a></li>
<li><a href="http://et.wcu.edu/aidc/BioWebPages/Biometrics_Keystroke.html">http://et.wcu.edu/aidc/BioWebPages/Biometrics_Keystroke.html</a></li>
<li><a href="http://www.computereconomics.com/custom.cfm?name=postPaymentGateway.cfm&#038;id=1185">http://www.computereconomics.com/custom.cfm?name=postPaymentGateway.cfm&#038;id=1185</a></li>
</ul>
<p><u><strong>Vendor </strong><strong>products:</strong></u></p>
<ul>
<li><a href="http://www.biopassword.com/index.php">http://www.biopassword.com/index.php</a></li>
<li><a target="_blank" href="http://www.imagicsoftware.com">http://www.imagicsoftware.com</a></li>
<li><a href="http://www.deepnetsecurity.com/">http://www.deepnetsecurity.com/</a></li>
</ul>
]]></content:encoded>
      <pubDate>Mon, 19 Feb 2007 14:00:11 +0000</pubDate>
      <category domain="http://securityratty.com/tag/keystroke dynamics">keystroke dynamics</category>
      <category domain="http://securityratty.com/tag/dynamics">dynamics</category>
      <category domain="http://securityratty.com/tag/keystroke">keystroke</category>
      <category domain="http://securityratty.com/tag/speech dynamics">speech dynamics</category>
      <category domain="http://securityratty.com/tag/keystroke dynamics systems">keystroke dynamics systems</category>
      <category domain="http://securityratty.com/tag/authentication">authentication</category>
      <category domain="http://securityratty.com/tag/multifactor authentication implementations">multifactor authentication implementations</category>
      <category domain="http://securityratty.com/tag/authentication factors">authentication factors</category>
      <category domain="http://securityratty.com/tag/biometric authentication">biometric authentication</category>
      <source url="http://securityrenaissance.com/2007/02/19/that-thing-you-do-%e2%80%93-keystroke-dynamics/">That thing you do keystroke dynamics</source>
    </item>
  </channel>
</rss>
