Intruder detector: A continuous authentication tool to model user behavior

Leslie C. Milton, Atif M. Memon · 2016

This paper presents techniques to continuously authenticate users as they interact with web-based software. Unique behavioral footprints, indicating patterns of use for groups of users, are captured from web server log files and integrated into an n-gram model. These statistical language models provide sequences and sub-sequences of user interaction, ordering, and temporal relationships. When users interact with web-based software, their stored usage profile is compared to their current interactions. Deviations may indicate malicious activity. We use our innovative tool, Intruder Detector (ID) to generate the profiles. Afterwards, we use various measures-of-effectiveness techniques to understand the feasibility of our approach. Our empirical study shows that session length and the prevalence of user data significantly affect the model's ability to correctly classify users.

Read the paper · More papers on PaperTik