Enhancing Security through Multi-Factor User Behavior Identification: Moving Beyond the Use of the Longest Common Subsequence (LCS)
Boumedyen Shannaq, Mohanaad Shakir · Informatica · 2024
The proposed approach comprises a set of strategies and tools to protect user-sensitive data, such as passwords, from unauthorized access, misuse, or loss. It aims to identify unauthorized users, often attackers who have obtained passwords, attempting to change authorized user passwords. By employing the Longest Common Subsequence (LCS) algorithm, the proposed method compares the current user password (AUP) with the unauthorized user's intended password update (UUP). This comparison reveals shared patterns between the two passwords, aiding in detecting unauthorized access attempts. For example, recurring patterns in password updates could serve as biometric security factors, allowing for the identification of user actions when updating sensitive data like passwords. This study enhances the CR approach associated with Electronic Personal Synthesis Behavior (EPSB) by introducing the Utilized Longest Common Subsequence (LCS) to address challenges such as the unavailability of user password history and password length. Our experiments indicate that the CR fails to identify the authorized user in 75 users and succeeds only 52% of cases when unauthorized users attempt to change the password. In contrast, our proposed method fails only 28.66% and succeeds with 102% of the time out of 141 data tests. Thus, the proposed algorithm is more effective to implement and could improve security levels significantly.