# User Authentication using Combination of Behavioral Biometrics over the Touchpad acting like Touch screen of Mobile Device

3 pressure time (ms) H1 H2 H3 H4 H5 H6 H7 H8 H9 H10 I1 I2 I3 I4 I5 I6 I7 I8 I9 Figure 1. Hold-time and Inter-key for a 10-digit number 3.3 Data Structuring Considering the finger pressure value, this value is obtained in different manners from other values mentioned above. Since the pressing area is not a single small point but it consists of multiple points on the pad, therefore, there are multiple pressing values over the pressed pad for each pressed digit. Thus, the average value of these multiple pressing values is used as the representative for one pressing digit, as shown in Figure 2. As same as other vectors, the vector of the finger pressure values is constructed as follows. P i, j FP i = [ Pi, 1, Pi,2,..., Pi, 10] Where denotes the average value of finger pressure values at the round i of digit j. Since this experiment is interested in using both hold-time and inter-key, vectors of each value will be constructed to determine its characteristics before the combination of these two values is determined the action effect of hold-time and inter-key. Considering the hold-time values of each person that presses one time for a 10-digit number, a vector in R R... R (10 terms) when R + is the set of all positive real numbers is created and can be written as follows. p 1 p p 5 p 3 2 p 4 p... p N N N p k k= Pi j = 1, Where digit j. H i, j HT i = [ Hi, 1, H i,2,..., Hi, 10] denotes the hold-time at the round i of As same as the hold-time value, the feature of the inter-key which is the interval duration between the two successive key, will be generated nine values for one time press of 10 digits. Thus, a vector in R R... R (9 terms) when R + is the set of all positive real numbers is created and can be written as follows. Where digit j. I i, j IK i = [ Ii, 1, I i,2,..., Ii, 9 ] denotes the inter-key at the round i of In order to determine the interaction among the hold-time and the inter-key, the concatenation of HT vector i IK and i is performed as follows. Figure 2. Calculation method of the finger pressure value 3.4 Analyzing Features After transforming the data, we investigated the preliminary feasibility of these behavioral biometrics by k-nn classification method that is widely used in data analysis [8] [11]. In k-nn classification the similarity between a validation sample (testing set) vector and reference vectors (training set) are computed using Euclidean distances. The class of feature vector is determined by selecting the class that has majority among the k- nearest neighbors; these are called k-nearest neighbors [8]. Since the total size of a data set is vector values for each person, thus, this set was divided into two groups for in the analytical process; two-third for training set (20 vectors), and one third for testing set (10 vectors). The pattern classification test was performed with one user acting as the valid user, while all others are acting as impostors. ( HT IK) i = [ Hi, 1, H i,2,..., Hi,10, Ii,1, Ii,2,..., Ii, 9] 84

4 In all biometrics, the measurement values to assess the performance of keystroke dynamics are defined as following: False Acceptance Rate (FAR) refers to the percentage of imposter was accepted by the system. False Rejection Rate (FRR) refers to the percentage of authorized users was rejected from the system. Equal Error Rate (EER) refers to the rate at which both accept and reject errors are equal. Moreover, this value is used to compare the performance of different biometric techniques. 7. Results Equal Error Rate (%) H I P HI HIP HP Features Figure 3. Equal Error Rate of each feature Figure 3 shows the EER values of all biometric measurement: the hold-time (H), the inter-key (I), the finger pressure (P). Additionally, the interactions among these metrics are considered; these are (1) keystroke dynamics which is the interaction between the hold-time and the inter-key (HI), (2) interaction between the hold-time and the finger pressure (HP), and (3) the interaction among three factors (HIP). Consider each main biometric according to Figure 3, the EER value of the hold-time is %, the inter-key is 35%, and the finger pressure has the lowest EER value, 1%. These numbers determine that the accuracy to identify a person can be obtained using the finger pressure value, and the alternative method is to apply the behavior of the hold-time or the inter-key. Referring to Figure 3, the interaction of biometrics is also considered, the results show that the best measurement value is obtained from the interaction between hold-time and finger pressure methods. This method has the EER value as same as the EER value of the finger pressure value, 1%. However, the interaction among three biometrics are also efficient because the EER value is only 9% while using the hold-time and the inter-key behavior does not be a good choice to identify persons since the EER value is 27% Discussion As the fact that the use of mobile devices is rapidly growth and developed, the motivation of stealing is also increased. Therefore, in order to protect the mobile devices, in every type of mobile hardware, the authentication system was implemented. One method to authenticate the mobile users is the use of biometric value, measured from the biometrics methods. The results in this paper that measure the EER values, using k-nn method, from three different behavior measurement values: the hold-time (H), the inter-keys (I), the finger pressure (P) shows that using the finger pressure as the indicator to identify users is the best measurement value although [10] had proposed that the accuracy to identify users can be obtained from the interaction of all three factors (HIP) analyzed by the component-wise verification scheme. Additionally, using the interaction among the hold-time and the finger pressure is also another choice to identify users with high accuracy, in order to protect any forges because the accuracy rate is 99% which is somehow much better than using the keystroke dynamics that analyzed by FF-MLP proposed by [7]. Nevertheless, [8] proposed that the keystroke dynamics can also be applied to identify users with high accuracy, 99%, under the use of the k-nn analytical method. 9. Conclusion Since mobile devices are developed to serve various functions, thus important data may be stored in the mobile memory card. In order to protect those information and mobile system from unauthorized users, the authentication system must be installed unavoidably. Although there are various authenticate methods, using bio data is one of the most interesting area to be applied. Additionally, the development of the mobile system is moving forward to the touch screen system for user friendly and quick access mechanism. Therefore, this paper focuses on the study of implementing the Biometric measurement to identify users. We investigate the potential of each biometrics behavioral by individual and couple, comprise with the hold-time, the inter-key, and the finger pressure. The results have shown that using only the finger pressure with the k-nn analytical method can indicate users with accuracy rate as 99% which is the same as using the combination of the hold-time and the finger pressure. However, the interaction of all three metrics is another alternative method to identify users since the correctness of the identifying mechanism is up to 90%. Therefore, implementing these alternative methods as a 85

5 part of the authentication system of the mobile devices can assure that the system is well protected and difficult to be broken by any imposters. 10. References [1] GSMWorld.com:WorldCellularSubscribers [2] S. Nanavati, M. Thieme, and R. Nanavati, Biometrics identity verification in a networked world, John Wiley & Sons, 2002 [3] N.L. Clarke and S.M. Furnell, Authentication of users on mobile telephones A survey of attitudes and practices, Computers & Security, October 2005, Vol.24, pp [4] [5] R. Gaines, W. Lisowski, S. Press and N. Shapiro, Authentication by keystroke timing: some preliminary results. Rand Report R-2560-NSF, Rand Corporation California, [6] M.S. Obaidat and B. Sadom, Verification of Computer Users Using Keystroke Dynamics, IEEE Transactions on Systems, Man, and Cybernetics, Part B: Cybernetics, April 1997, Vol. 27, pp [7] N.L. Clarke and S.M. Furnell, Authenticating mobile phone users using keystroke analysis, International Journal of Information Security, Springer-Verlag, Berlin, Heidelberg, December 2006, pp [8] J. Mantyiarvi, J. koivumaki and P. Vuori, keystroke recognition for virtual keyboard, Proceeding of international Conference on Multimedia and Expo, November 11, 2002, Vol. 2, pp [9] S. Karatzouni and N. Clark, New Approaches for security, Privacy and Trust in Complex Environments, Springer Boston, Vol.32, [10] N J Grabham and N M White, Use of a Novel Keypad Biometric for Enhanced User Identity Verification, IEEE International Instrumentation and Measurement Technology Conference, Victoria, Vancouver Island, Canada, May 12-15, [11] S.R. Kulkarni, G. Lugosi, and S. S. Venkatesh, Learning Pattern Classification - Survey, IEEE Transaction on Information Theory, October 1998, Vol.44, pp

### User Authentication/Identification From Web Browsing Behavior

User Authentication/Identification From Web Browsing Behavior US Naval Research Laboratory PI: Myriam Abramson, Code 5584 Shantanu Gore, SEAP Student, Code 5584 David Aha, Code 5514 Steve Russell, Code