Rutgers computer scientists work to strengthen online security
If you forget your password when logging into an e-mail or online shopping Web site, the site will likely ask you a security question: What is your mother's maiden name? Where were you born? The trouble is that such questions are not very secure. More people than you may think will know your answers. And if they don't, it might not be hard to search for it online or even make a lucky guess.
But Rutgers computer scientists are testing a new tactic that could be both easier and more secure.
"We call them activity-based personal questions," said Danfeng Yao, assistant professor of computer science in the Rutgers School of Arts and Sciences. "Sites could ask you, 'When was the last time you sent an e-mail?' Or, 'What did you do yesterday at noon?'"
Yao and her students have been testing how resistant these activity questions are to "attack," – computer security lingo for when an intruder answers them correctly and gains access to personal information such as e-mails or to do online shopping or banking.
Early studies suggest that questions about recent activities are easy for legitimate users to answer but harder for potential intruders to find or guess, Yao said.
"We want the question to be dynamic," she said. "The questions you get today will be different from the ones you would get tomorrow."
Rutgers doctoral student Huijun Xiong and visiting undergraduate student Anitra Babic are presenting the group's preliminary results in a workshop at this week's Association for Computing Machinery Conference on Computer and Communications Security. Babic is a senior at Chestnut Hill College in Philadelphia and participated in a summer research program at Rutgers.
Yao said she gave four students in her lab a list of questions related to network activities, physical activities and opinion questions, and then told them to "attack" each other.
"We found that questions related to time are more robust than others. Many guessed the answer to the question, 'Who was the last person you sent e-mail to?' But fewer were able to guess, 'What time did you send your last e-mail?'"
Yao explains that it should not be difficult for an online service provider to formulate these kinds of security questions by looking at its users' e-mail, calendar activities or previous transactions. Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy.
Yao is proposing further studies to determine the practicality of the new approach and the best way to implement it.
Source: Rutgers University
Related
- Controlling the language of securityFri, 18 Sep 2009, 10:13:32 EDT
- Wake-up call: Draft security pub looks at cell phones, PDAsThu, 10 Jul 2008, 11:42:26 EDT
- Dartmouth College researchers help set security standards for the InternetWed, 8 Jul 2009, 11:09:45 EDT
- How secure is your network? NIST model knowsWed, 23 Jul 2008, 15:14:41 EDT
- New publication offers security tips for WiMAX networksWed, 7 Oct 2009, 9:08:48 EDT
Other sources
- Computer scientists work to strengthen online securityfrom PhysorgMon, 9 Nov 2009, 15:21:42 EST
- Computer Scientists Work To Strengthen Online Securityfrom Science DailyMon, 9 Nov 2009, 14:14:14 EST
- Rutgers computer scientists work to strengthen online securityfrom Science CentricMon, 9 Nov 2009, 11:21:12 EST
Latest Science Newsletter
Get the latest and most popular science news articles of the week in your Inbox!Learn more about
Popular science news articles
- Facebook profiles capture true personality, according to new psychology research
- Shape shifters: Researchers create new breed of antennas
- Typhoon Nida's cloud tops dropping as it zigzags in wind shear
- Will copper keep us safe from the superbugs?
- Homicide rates linked to trust in governement, sense of belonging, study suggests
- First-ever blueprint of a minimal cell is more complex than expected
- Brain's fear center is equipped with a built-in suffocation sensor
- Implant-based cancer vaccine is first to eliminate tumors in mice
- New study finds men and women may respond differently to danger
- Tough yet stiff deer antler is materials scientist's dream
- Implant-based cancer vaccine is first to eliminate tumors in mice
- Study shows new brain connections form rapidly during motor learning
- Brain scan study shows cocaine abusers can control cravings
- Study sheds light on brain's fear processing center
- First-ever blueprint of a minimal cell is more complex than expected
- New evidence that dark chocolate helps ease emotional stress
- African desert rift confirmed as new ocean in the making
- Nanoparticles used in common household items caused genetic damage in mice
- New study links vitamin D deficiency to cardiovascular disease and death
- Polyphenols and polyunsaturated fatty acids boost the birth of new neurons