A Few-Shot Practical Behavioral Biometrics Model for Login Authentication in Web Applications
Jess Solano, Lizzy Tengana, Alejandra Castelblanco, Esteban Rivera, Christian López, Martín Ochoa · 2020
Risk based authentication has been advocated as complement to traditional authentication mechanisms in order to raise the bar against attackers in possession of stolen credentials.Behavioral biometrics has received attention in the literature in the past decade, however the best results have been obtained in the so-called continuous setting and with enough training data, usually spanning several hours of user interaction.In this paper we explore the more challenging scenario of behavioral biometrics as an effective risk-based authentication technique using both mouse and keyboard information at login time (static authentication), assuming only between 3 and 7 login sessions per user for training.In a controlled but realistic experiment with 89 subjects we achieve a FRR of 10.73% and FAR of 23.34% for a model trained using only 5 login attempts, each performed in less than 30 seconds on average.We also evaluate our prototype with 2000 users from production data in the banking domain.