Computer scientists work to strengthen online security

November 9, 2009

If you forget your password when logging into an e-mail or online shopping Web site, the site will likely ask you a security question: What is your mother's maiden name? Where were you born?

The trouble is that such questions are not very secure. More people than you may think will know your answers. And if they don't, it might not be hard to search for it online or even make a lucky guess.

But Rutgers computer scientists are testing a new tactic that could be both easier and more secure.

"We call them activity-based personal questions," said Danfeng Yao, assistant professor of computer science in the Rutgers School of Arts and Sciences. "Sites could ask you, 'When was the last time you sent an e-mail?' Or, 'What did you do yesterday at noon?'"

Yao and her students have been testing how resistant these activity questions are to "attack," - computer security lingo for when an intruder answers them correctly and gains access to personal information such as e-mails or to do online shopping or banking.

Early studies suggest that questions about recent activities are easy for legitimate users to answer but harder for potential intruders to find or guess, Yao said.

"We want the question to be dynamic," she said. "The questions you get today will be different from the ones you would get tomorrow."

Rutgers doctoral student Huijun Xiong and visiting undergraduate student Anitra Babic are presenting the group's preliminary results in a workshop at this week's Association for Computing Machinery Conference on Computer and Communications Security. Babic is a senior at Chestnut Hill College in Philadelphia and participated in a summer research program at Rutgers.

Yao said she gave four students in her lab a list of questions related to network activities, physical activities and opinion questions, and then told them to "attack" each other.

"We found that questions related to time are more robust than others. Many guessed the answer to the question, 'Who was the last person you sent e-mail to?' But fewer were able to guess, 'What time did you send your last e-mail?'"

Yao explains that it should not be difficult for an online service provider to formulate these kinds of security questions by looking at its users' e-mail, calendar activities or previous transactions. Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy.

Yao is proposing further studies to determine the practicality of the new approach and the best way to implement it.

Source: Rutgers University (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • paulthebassguy - Nov 09, 2009
    • Rank: not rated yet
    But I can't remember exactly when I sent my last email?! I think that this is a nice concept but it will fail due to the actual practicality of it.

    Also "Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy" - NLP algorithms are notorious for wording incomprehensible sentences and not understanding normal sentences properly when there is the slightest amount of ambiguity.

November 9, 2009 all stories

Comments: 1

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Study finds you get what you pay for with online Q & A sites
    created Apr 09, 2008 | popularity not rated yet | comments 0
  • Users of Yahoo Answers seek advice, opinion, expertise
    created Apr 22, 2008 | popularity not rated yet | comments 0
  • Yahoo! launches Web answering site
    created Dec 08, 2005 | popularity not rated yet | comments 0
  • Twitter hacked by old technique -- again
    created Jul 15, 2009 | popularity not rated yet | comments 0
  • Rational or Random? Model Shows How People Send E-Mails
    created Nov 19, 2008 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • LabVIEW simulator (Virtual electrolysis machine)
    created 21 hours ago
  • Bill Gates
    created Dec 18, 2009
  • Ti 89 Graphing help
    created Dec 17, 2009
  • sedumi for semidefinite optimization
    created Dec 17, 2009
  • More from Physics Forums - Computing & Technology

Other News

Google has a digital foothold in France

Google gets digital foothold in France

Technology / Internet

created 15 hours ago | popularity 5 / 5 (1) | comments 0

Despite fierce resistance to Google's plans to digitise the world's books, observers say it is well placed to start scanning Europe's cultural treasures -- beginning in France, where the US giant got a digital ...


Hollywood adds money, talent to made-for-Web shows (AP)

Hollywood adds money, talent to made-for-Web shows

Technology / Internet

created 15 hours ago | popularity 2 / 5 (1) | comments 0

(AP) -- Web sites that buy original video clips often pay so little that "The Bannen Way," a flashy crime thriller debuting online, looked destined to be made poorly if it could be made at all.


The high speed train named Sapsan moves along the tracks at a station in Saint-Petersburg

Russian railways enter modern age with new express

Technology / Engineering

created 15 hours ago | popularity 3.8 / 5 (4) | comments 0

Famed for the legendary trains that clank across seven time zones on its Trans-Siberian railroad, Russia this week entered the modern railway age with its first high-tech express train.


Australian government to introduce Internet filter (AP)

Australian government to introduce Internet filter

Technology / Internet

created Dec 15, 2009 | popularity 3.5 / 5 (19) | comments 9

(AP) -- Australia plans to introduce an Internet filtering system to block obscene and crime-linked Web sites despite concerns it will curtail freedoms and won't completely work.


Nissan Leaf

Electric cars rolling out

Technology / Energy

created Dec 16, 2009 | popularity 4.4 / 5 (15) | comments 7

(PhysOrg.com) -- Electric vehicles are far from new, but we are still a long way from electric cars being the norm. Now two new electric cars may bring that goal a step closer.