Secure data collection for keystroke dynamics

Michael Manno, Daqing Hou · 2025

Traditional username and password techniques does not continually monitor usage behavior over time. Currently, the authentication process occurs at login and does not distinguish between users after each login over the course of the session. The problem is credentials can be misused, stolen, or spoofed, and do not always reflect the individual using them after login. Behavioral biometrics is the study of unique patterns in human behavior for the purpose of identification, authentication, and continuous monitoring. Traditional authentication methods that typically require a one-time verification are knowledge-based, requiring a username and password, are based on “what you know”, where behavioral biometrics verify a user based on “what you are”. Unlike physical biometrics such as fingerprints, iris scans, facial recognition, and voice recognition, which are based on physical traits, behavioral biometrics is based on analyzing and identifying unique patterns in human behavior to verify an individual's identity. Traditional keystroke dynamic key loggers capture the keys as a user types, along with several timing measurements such as flight time, dwell time, and latency. The continued keystroke logging used for authentication introduces the issue of trust and security. Some users may perceive keystroke dynamics as invasive and may be hesitant to provide real-world computer usage during collection. Key logger files are also a vulnerability itself, allowing for the possibly of a replay attack if discovered. Our objective is to address these concerns by developing a segmented data collection process for keystroke dynamics that results in a trusted keystroke dynamic dataset.

Read the paper · More papers on PaperTik