F ig hting Co e rc io n Atta c ks using Skin Co nduc ta nc e Mo - - PowerPoint PPT Presentation

f ig hting co e rc io n atta c ks using skin co nduc ta
SMART_READER_LITE
LIVE PREVIEW

F ig hting Co e rc io n Atta c ks using Skin Co nduc ta nc e Mo - - PowerPoint PPT Presentation

F ig hting Co e rc io n Atta c ks using Skin Co nduc ta nc e Mo b ile Co nte xtua l Se c urity F ighting Co e r c io n Attac ks in Ke y Ge ne r atio n using Skin Co nduc tanc e Pa ya s Gupta a nd De b in Ga o , Sing a po


slide-1
SLIDE 1
slide-2
SLIDE 2

 F

ig hting Co e rc io n Atta c ks using Skin Co nduc ta nc e

 Mo b ile Co nte xtua l Se c urity

slide-3
SLIDE 3

 F

ighting Co e r c io n Attac ks in Ke y Ge ne r atio n using Skin Co nduc tanc e

› Pa ya s Gupta a nd De b in Ga o , Sing a po re Ma na g e me nt Unive rsity, › 19th USE NI X Se c urity Sympo sium, 2010

slide-4
SLIDE 4

4

USB Biometrics Password

Coercion Attack

Unforgettability Unforgeability High entropy

1 0 1 1 0 0 0 1 0 1 0 1 1 0 1 1 0 1 1 0 1 1 0 1 1 0 0 1 0 1 0 1 0 1 0 1 0 1 0 1

slide-5
SLIDE 5

 Ba nk Va ult  T

  • p Se c re t L

a b

 Airpla ne Co c kpit

slide-6
SLIDE 6

6

slide-7
SLIDE 7

7

Existing Approach

Authe ntic a te d

Voic e

Co rre c t Crypto g ra phic ke y

Problem with the : Coercion Attack

slide-8
SLIDE 8

 Co e rc io n-re sista nt se c urity sc he me

› Use r do e s no t ha ve a c ho ic e › Use r do e s no t ha ve the c a pa b ility

 Assumptio n: Atta c ke r kno ws ho w the

syste m wo rks

 I

mplic a tio ns: Atta c ke r will no t c o e rc e the use r

 Pa nic Pa sswo rds [Cla rk ‘08]

› Ca n b e use d fo r a uthe ntic a ting unde r dure ss

8

slide-9
SLIDE 9

Along with Voice, use Skin Conductance as Emotional Response Parameter

Cor r e c t

Crypto g ra phic ke y

Authe ntic a te d

Vo ic e & Skin Co nduc ta nc e

T ime Skin Co nduc ta nc e

Skin Co nduc ta nc e De vic e

9

slide-10
SLIDE 10

Along with Voice, use Skin Conductance as Emotional Response Parameter

Inc or r e c t

Crypto g ra phic ke y No t

Authe ntic a te d

Voic e & Skin Conduc tanc e

T ime Skin Co nduc ta nc e

Skin Co nduc ta nc e De vic e

10

slide-11
SLIDE 11

11

 Ho w to sho w up re sults a nd to pe rfo rm

use r study?

slide-12
SLIDE 12

 Unde rg ra dua te a nd g ra dua te stude nts

in the a g e fro m 18 to 28.

 43 pa rtic ipa nts

› 4 pa rtic ipa nts re mo ve d the me a suring de vic e fro m the ir fing e rs whe n the y we re ne rvo us during the e xpe rime nt.

 T

he re fo re , suc c e ssful pa rtic ipa nts – 39

› 22 ma le a nd 17 fe ma le

12

slide-13
SLIDE 13

13

He a rt ra te ta g s

slide-14
SLIDE 14

 Ob je c tive

› Mo nito r Skin Co nduc ta nc e

No rma l Stre sse d

14

slide-15
SLIDE 15

15

F a lse fe e db a c k o f He a rt Ra te

slide-16
SLIDE 16

16

slide-17
SLIDE 17

17

slide-18
SLIDE 18

18

Do not touch the ‘X’ key of the keyboard

slide-19
SLIDE 19

19

It was your fault Who will pay for the device? How will I recover my data? Yeah it was my mistake, I pressed the X key of your keyboard. I am ready to help you!!! I am sorry, but I did not press X key. Your experiment sucks, your laptop sucks, moreover you suck

slide-20
SLIDE 20

Examiner leaves the room, leaving the subject alone

20

slide-21
SLIDE 21

21

Subject sits in-front of a PC and is asked to type a few sentences.

slide-22
SLIDE 22

The core of the experiment begins when the PC shuts off as the subject is typing a letter

22

slide-23
SLIDE 23

As a result, subject succumbs to stress.

23

slide-24
SLIDE 24

Examiner enters the room

24

slide-25
SLIDE 25

And, falsely accused the subject for inappropriate handling of PC and corresponding data loss

25