Computer scientists work to strengthen online security

November 9, 2009

If you forget your password when logging into an e-mail or online shopping Web site, the site will likely ask you a security question: What is your mother's maiden name? Where were you born?

The trouble is that such questions are not very secure. More people than you may think will know your answers. And if they don't, it might not be hard to search for it online or even make a lucky guess.

But Rutgers computer scientists are testing a new tactic that could be both easier and more secure.

"We call them activity-based personal questions," said Danfeng Yao, assistant professor of computer science in the Rutgers School of Arts and Sciences. "Sites could ask you, 'When was the last time you sent an e-mail?' Or, 'What did you do yesterday at noon?'"

Yao and her students have been testing how resistant these activity questions are to "attack," - computer security lingo for when an intruder answers them correctly and gains access to personal information such as e-mails or to do online shopping or banking.

Early studies suggest that questions about recent activities are easy for legitimate users to answer but harder for potential intruders to find or guess, Yao said.

"We want the question to be dynamic," she said. "The questions you get today will be different from the ones you would get tomorrow."

Rutgers doctoral student Huijun Xiong and visiting undergraduate student Anitra Babic are presenting the group's preliminary results in a workshop at this week's Association for Computing Machinery Conference on Computer and Communications Security. Babic is a senior at Chestnut Hill College in Philadelphia and participated in a summer research program at Rutgers.

Yao said she gave four students in her lab a list of questions related to network activities, physical activities and opinion questions, and then told them to "attack" each other.

"We found that questions related to time are more robust than others. Many guessed the answer to the question, 'Who was the last person you sent e-mail to?' But fewer were able to guess, 'What time did you send your last e-mail?'"

Yao explains that it should not be difficult for an online service provider to formulate these kinds of security questions by looking at its users' e-mail, calendar activities or previous transactions. Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy.

Yao is proposing further studies to determine the practicality of the new approach and the best way to implement it.

Source: Rutgers University (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • paulthebassguy - Nov 09, 2009
    • Rank: not rated yet
    But I can't remember exactly when I sent my last email?! I think that this is a nice concept but it will fail due to the actual practicality of it.

    Also "Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy" - NLP algorithms are notorious for wording incomprehensible sentences and not understanding normal sentences properly when there is the slightest amount of ambiguity.

November 9, 2009 all stories

Comments: 1

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Study finds you get what you pay for with online Q & A sites
    created Apr 09, 2008 | popularity not rated yet | comments 0
  • Users of Yahoo Answers seek advice, opinion, expertise
    created Apr 22, 2008 | popularity not rated yet | comments 0
  • Yahoo! launches Web answering site
    created Dec 08, 2005 | popularity not rated yet | comments 0
  • Twitter hacked by old technique -- again
    created Jul 15, 2009 | popularity not rated yet | comments 0
  • Rational or Random? Model Shows How People Send E-Mails
    created Nov 19, 2008 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Buying a Wii - what do I want?
    created 21 hours ago
  • iTouch apps
    created Nov 27, 2009
  • Sixth sense technology
    created Nov 26, 2009
  • kindle e-reader and scientific papers
    created Nov 24, 2009
  • More from Physics Forums - Computing & Technology

Other News

Gift Guide: Adventures in the video game aisle (AP)

Gift Guide: Adventures in the video game aisle

Technology / Software

created 16 minutes ago | popularity not rated yet | comments 0

(AP) -- The video game aisle can be intimidating for aspiring Santas who haven't touched a joystick since "Pong." But it has something for everyone: riveting solo adventures, online multiplayer battles and ...


Wikipedia

Report claims Wikipedia losing editors in droves

Technology / Internet

created 6 hours ago | popularity 4.3 / 5 (8) | comments 1

(PhysOrg.com) -- The findings of a Spanish study claiming that Wikipedia's editors are leaving at an alarming rate have been refuted by the Wikimedia Foundation and by Wikipedia co-founder Jimmy Wales.


Pickin' Up Good Vibrations to Produce Green Electricity

Pickin' Up Good Vibrations to Produce Green Electricity

Technology / Engineering

created 2 hours ago | popularity 5 / 5 (1) | comments 0

(PhysOrg.com) -- Vibrations from the environments we live and work in could be much more widely harnessed as a clean source of electricity, due to cutting-edge UK research.


Online retailers rev up deals to keep up momentum (AP)

Online retailers rev up deals to keep up momentum

Technology / Business

created 1hour ago | popularity not rated yet | comments 0

(AP) -- Retail Web sites kept amping up the deals Monday, the first day after the Thanksgiving holiday, to try to maintain the long weekend's strong online sales.


NRL's Ion Tiger sets 26-hour flight endurance record

Hydrogen-Powered Ion Tiger Sets 26-hour Flight Endurance Record

Technology / Energy

created 2 hours ago | popularity 5 / 5 (1) | comments 0

The Naval Research Laboratory's Ion Tiger, a hydrogen-powered fuel cell unmanned air vehicle (UAV), has flown 26 hours and 1 minute carrying a 5-pound payload, setting another unofficial flight endurance record ...