Évaluation des performances et de la sécurité des systèmes biométriques comportementales
Yris Brice Wandji Piugie · HAL (Le Centre pour la Communication Scientifique Directe) · 2023
Behavioral biometrics offers new prospects for strengthening security and enhancing the user experience by analyzing users' interactions with IT systems. So it is an approach for identification and authentication based on the analysis of users' interactions with computer systems. While it can enhance security and improve the user experience, it raises privacy concerns. This Ph.D. thesis proposes a generic method for analyzing behavioral biometrics, with applications such as keystroke dynamics and human activities. Additionally, it also explores the effectiveness of Classical Machine Learning techniques for identification, as well as Deep Learning methods for user authentication based on their behaviors, with a focus on human activity on smartphones and keystroke dynamics on laptops. This Ph.D. thesis also proposes an innovative method for processing raw biometric data considered as time series. This provides far results to those already available. The time series processing consists of transforming the behavioral biometric raw data into a 2D image color. This transformation process keeps all the characteristics of the behavioral signal. Time series does not receive any filtering operation with this transformation and the method is reversible. This signal-to-image transformation allows us to use the 2D convolutional networks to build efficient deep feature vectors. This allows us to compare these feature vectors to the reference template vectors to compute the performance metric. We evaluate the performance of the authentication system in terms of Equal Error Rate (EER) on benchmark datasets and we show the efficiency of the approach. The results demonstrate that these approaches can achieve good performance, but also highlight potential privacy issues. It shows the effectiveness of this innovative approach in enhancing security without disrupting the user experience. Data security is crucially important in ensuring the safety of users and the confidentiality of their information in the field of cybersecurity. This is why many companies have begun to implement authentication systems to control and restrict access to their data. However, some traditional authentication methods have proved insufficient to ensure adequate data protection, which is why behavioral biometrics has gained importance. Despite promising results and a wide range of applications, biometric systems remain vulnerable to malicious attacks, particularly presentation attacks. That is why, in this Ph.D. thesis, we set out to deploy a presentation attack against an authentication system based on behavioral biometrics. Our approach is to use the most popular temporal adversarial generators (TimeGAN) to create synthetic behavioral biometric data, which could be used to impersonate an authorized user. These synthetic data are generated while preserving temporal dynamics, meaning that new sequences respect the original relationships between variables over time. Finally, we validated both the original data and the synthetic behavioral biometrics generated. This validation was carried out using qualitative and quantitative similarity measures, as well as by assessing predictive ability. In addition, an authentication system was set up to assess the effectiveness of the data generated. The results obtained, together with a visual inspection, indicate that TimeGAN can indeed generate behavioral patterns that can be used to fool and consequently test behavioral authentication systems.