If you forget your password when logging into an e-mail or online shopping Web site, the site will likely ask you a security question: What is your mother’s maiden name? Where were you born?
The trouble is that such questions are not very secure. More people than you may think will know your answers. And if they don’t, it might not be hard to search for it online or even make a lucky guess.
But Rutgers computer scientists are testing a new tactic that could be both easier and more secure.
“We call them activity-based personal questions,” said Danfeng Yao, assistant professor of computer science in the Rutgers School of Arts and Sciences. “Sites could ask you, ‘When was the last time you sent an e-mail?’ Or, ‘What did you do yesterday at noon?’”
Yao and her students have been testing how resistant these activity questions are to “attack,” – computer security lingo for when an intruder answers them correctly and gains access to personal information such as e-mails or to do online shopping or banking.
Early studies suggest that questions about recent activities are easy for legitimate users to answer but harder for potential intruders to find or guess, Yao said.
“We want the question to be dynamic,” she said. “The questions you get today will be different from the ones you would get tomorrow.”
Rutgers doctoral student Huijun Xiong and visiting undergraduate student Anitra Babic are presenting the group’s preliminary results in a workshop at this week’s Association for Computing Machinery Conference on Computer and Communications Security. Babic is a senior at Chestnut Hill College in Philadelphia and participated in a summer research program at Rutgers.
Yao said she gave four students in her lab a list of questions related to network activities, physical activities and opinion questions, and then told them to “attack” each other.
"We found that questions related to time are more robust than others. Many guessed the answer to the question, ‘Who was the last person you sent e-mail to?’ But fewer were able to guess, ‘What time did you send your last e-mail?’”
Yao explains that it should not be difficult for an online service provider to formulate these kinds of security questions by looking at its users’ e-mail, calendar activities or previous transactions. Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy.
Yao is proposing further studies to determine the practicality of the new approach and the best way to implement it.
Yao’s work is funded in part by grants from the National Science Foundation.
Carl Blesch | EurekAlert!
Powerful IT security for the car of the future – research alliance develops new approaches
25.05.2018 | Universität Ulm
Supercomputing the emergence of material behavior
18.05.2018 | University of Texas at Austin, Texas Advanced Computing Center
The more electronics steer, accelerate and brake cars, the more important it is to protect them against cyber-attacks. That is why 15 partners from industry and academia will work together over the next three years on new approaches to IT security in self-driving cars. The joint project goes by the name Security For Connected, Autonomous Cars (SecForCARs) and has funding of €7.2 million from the German Federal Ministry of Education and Research. Infineon is leading the project.
Vehicles already offer diverse communication interfaces and more and more automated functions, such as distance and lane-keeping assist systems. At the same...
A research team led by physicists at the Technical University of Munich (TUM) has developed molecular nanoswitches that can be toggled between two structurally different states using an applied voltage. They can serve as the basis for a pioneering class of devices that could replace silicon-based components with organic molecules.
The development of new electronic technologies drives the incessant reduction of functional component sizes. In the context of an international collaborative...
At the LASYS 2018, from June 5th to 7th, the Laser Zentrum Hannover e.V. (LZH) will be showcasing processes for the laser material processing of tomorrow in hall 4 at stand 4E75. With blown bomb shells the LZH will present first results of a research project on civil security.
At this year's LASYS, the LZH will exhibit light-based processes such as cutting, welding, ablation and structuring as well as additive manufacturing for...
There are videos on the internet that can make one marvel at technology. For example, a smartphone is casually bent around the arm or a thin-film display is rolled in all directions and with almost every diameter. From the user's point of view, this looks fantastic. From a professional point of view, however, the question arises: Is that already possible?
At Display Week 2018, scientists from the Fraunhofer Institute for Applied Polymer Research IAP will be demonstrating today’s technological possibilities and...
So-called quantum many-body scars allow quantum systems to stay out of equilibrium much longer, explaining experiment | Study published in Nature Physics
Recently, researchers from Harvard and MIT succeeded in trapping a record 53 atoms and individually controlling their quantum state, realizing what is called a...
25.05.2018 | Event News
02.05.2018 | Event News
13.04.2018 | Event News
25.05.2018 | Event News
25.05.2018 | Machine Engineering
25.05.2018 | Life Sciences