Computer scientists work to strengthen online security

November 9, 2009

If you forget your password when logging into an e-mail or online shopping Web site, the site will likely ask you a security question: What is your mother's maiden name? Where were you born?

The trouble is that such questions are not very secure. More people than you may think will know your answers. And if they don't, it might not be hard to search for it online or even make a lucky guess.

But Rutgers computer scientists are testing a new tactic that could be both easier and more secure.

"We call them activity-based personal questions," said Danfeng Yao, assistant professor of computer science in the Rutgers School of Arts and Sciences. "Sites could ask you, 'When was the last time you sent an e-mail?' Or, 'What did you do yesterday at noon?'"

Yao and her students have been testing how resistant these activity questions are to "attack," - computer security lingo for when an intruder answers them correctly and gains access to personal information such as e-mails or to do online shopping or banking.

Early studies suggest that questions about recent activities are easy for legitimate users to answer but harder for potential intruders to find or guess, Yao said.

"We want the question to be dynamic," she said. "The questions you get today will be different from the ones you would get tomorrow."

Rutgers doctoral student Huijun Xiong and visiting undergraduate student Anitra Babic are presenting the group's preliminary results in a workshop at this week's Association for Computing Machinery Conference on Computer and Communications Security. Babic is a senior at Chestnut Hill College in Philadelphia and participated in a summer research program at Rutgers.

Yao said she gave four students in her lab a list of questions related to network activities, physical activities and opinion questions, and then told them to "attack" each other.

"We found that questions related to time are more robust than others. Many guessed the answer to the question, 'Who was the last person you sent e-mail to?' But fewer were able to guess, 'What time did you send your last e-mail?'"

Yao explains that it should not be difficult for an online service provider to formulate these kinds of security questions by looking at its users' e-mail, calendar activities or previous transactions. Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy.

Yao is proposing further studies to determine the practicality of the new approach and the best way to implement it.

Source: Rutgers University (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • paulthebassguy - Nov 09, 2009
    • Rank: not rated yet
    But I can't remember exactly when I sent my last email?! I think that this is a nice concept but it will fail due to the actual practicality of it.

    Also "Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy" - NLP algorithms are notorious for wording incomprehensible sentences and not understanding normal sentences properly when there is the slightest amount of ambiguity.

November 9, 2009 all stories

Comments: 1

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Study finds you get what you pay for with online Q & A sites
    created Apr 09, 2008 | popularity not rated yet | comments 0
  • Users of Yahoo Answers seek advice, opinion, expertise
    created Apr 22, 2008 | popularity not rated yet | comments 0
  • Yahoo! launches Web answering site
    created Dec 08, 2005 | popularity not rated yet | comments 0
  • Twitter hacked by old technique -- again
    created Jul 15, 2009 | popularity not rated yet | comments 0
  • Rational or Random? Model Shows How People Send E-Mails
    created Nov 19, 2008 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

Other News

Panasonic develops direct methanol fuel cell system with high power output and durability

Technology / Energy

created 8 hours ago | popularity 4.6 / 5 (8) | comments 0

Panasonic Corporation announced it has developed a direct methanol fuel cell system which can produce an average power output of 20 W by increasing the output per cubic centimeter twice that of its previous prototype. Using ...


Chicken farm

Chicken waste turned to watts

Technology / Energy

created 15 hours ago | popularity 3.3 / 5 (8) | comments 3

A Nevada energy developer says it has developed an environmentally clean way of using animal waste from chicken farms across the state to light up homes and offices. Green Energy Solutions wants to convert ...


Comcast settles data discrimination lawsuit

Technology / Internet

created Dec 23, 2009 | popularity not rated yet | comments 3

(AP) -- Comcast will pay up to $16 million to settle a class-action lawsuit accusing the cable TV operator of delaying certain Internet traffic.


A man surfs the web at a cafe in Beijing, China where two Chinese bloggers have been fined for defamation

China bloggers fined for defamation: report

Technology / Internet

created 15 hours ago | popularity not rated yet | comments 0

Two Chinese bloggers were ordered to pay about 290,000 yuan (42,478 dollars) in compensation to the widow of film director Xie Jin for claiming he died in the arms of a prostitute, a report said Saturday.


NORAD is tracking Santa Claus's progress

Follow Santa Claus, courtesy Google and NORAD

Technology / Internet

created Dec 24, 2009 | popularity 2.7 / 5 (7) | comments 1

Santa Claus is coming to your town -- and NORAD is tracking him as he drops off presents around the world. The North American Aerospace Defense Command, which monitors the North American airspace, on Thursday ...