Computer scientists work to strengthen online security

November 9, 2009

If you forget your password when logging into an e-mail or online shopping Web site, the site will likely ask you a security question: What is your mother's maiden name? Where were you born?

The trouble is that such questions are not very secure. More people than you may think will know your answers. And if they don't, it might not be hard to search for it online or even make a lucky guess.

But Rutgers computer scientists are testing a new tactic that could be both easier and more secure.

"We call them activity-based personal questions," said Danfeng Yao, assistant professor of computer science in the Rutgers School of Arts and Sciences. "Sites could ask you, 'When was the last time you sent an e-mail?' Or, 'What did you do yesterday at noon?'"

Yao and her students have been testing how resistant these activity questions are to "attack," - computer security lingo for when an intruder answers them correctly and gains access to personal information such as e-mails or to do online shopping or banking.

Early studies suggest that questions about recent activities are easy for legitimate users to answer but harder for potential intruders to find or guess, Yao said.

"We want the question to be dynamic," she said. "The questions you get today will be different from the ones you would get tomorrow."

Rutgers doctoral student Huijun Xiong and visiting undergraduate student Anitra Babic are presenting the group's preliminary results in a workshop at this week's Association for Computing Machinery Conference on Computer and Communications Security. Babic is a senior at Chestnut Hill College in Philadelphia and participated in a summer research program at Rutgers.

Yao said she gave four students in her lab a list of questions related to network activities, physical activities and opinion questions, and then told them to "attack" each other.

"We found that questions related to time are more robust than others. Many guessed the answer to the question, 'Who was the last person you sent e-mail to?' But fewer were able to guess, 'What time did you send your last e-mail?'"

Yao explains that it should not be difficult for an online service provider to formulate these kinds of security questions by looking at its users' e-mail, calendar activities or previous transactions. Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy.

Yao is proposing further studies to determine the practicality of the new approach and the best way to implement it.

Source: Rutgers University (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • paulthebassguy - Nov 09, 2009
    • Rank: not rated yet
    But I can't remember exactly when I sent my last email?! I think that this is a nice concept but it will fail due to the actual practicality of it.

    Also "Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy" - NLP algorithms are notorious for wording incomprehensible sentences and not understanding normal sentences properly when there is the slightest amount of ambiguity.

November 9, 2009 all stories

Comments: 1

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Study finds you get what you pay for with online Q & A sites
    created Apr 09, 2008 | popularity not rated yet | comments 0
  • Users of Yahoo Answers seek advice, opinion, expertise
    created Apr 22, 2008 | popularity not rated yet | comments 0
  • Yahoo! launches Web answering site
    created Dec 08, 2005 | popularity not rated yet | comments 0
  • Twitter hacked by old technique -- again
    created Jul 15, 2009 | popularity not rated yet | comments 0
  • Rational or Random? Model Shows How People Send E-Mails
    created Nov 19, 2008 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Help with a camera choice
    created Nov 18, 2009
  • casio calculator that's similar to TI-89
    created Nov 08, 2009
  • Advice on what cell phone to get
    created Nov 08, 2009
  • Changing the language options on your phone.
    created Nov 03, 2009
  • More from Physics Forums - Computing & Technology

Other News

Suit over search-engine keywords tries new angle

Technology / Internet

created 13 hours ago | popularity 2.5 / 5 (2) | comments 0

(AP) -- A lawsuit in Wisconsin is bringing a fresh challenge to the practice of paying for keywords on Google and other search engines to boost one company's link over a rival's.


Screen of a computer featuring a search of the word "edition" on the home page of Google's website

Google books hearing set for February 18

Technology / Internet

created 15 hours ago | popularity not rated yet | comments 0

A US judge set February 18 for a hearing on the revised legal settlement between Google and US authors and publishers that would allow the Internet giant to scan and sell millions of books online.


Trust Linux!

Trust Linux!

Technology / Software

created 20 hours ago | popularity 4.3 / 5 (3) | comments 0

(PhysOrg.com) -- A team of researchers has implemented support for 'trusted computing' in a commercially available version of the open source operating system Linux, breaking new ground in the global drive ...


Newspapers are displayed at a newsstand

US newspaper ad revenue down nearly 28 percent

Technology / Business

created 14 hours ago | popularity not rated yet | comments 0

US newspaper advertising revenue fell by nearly 28 percent in the third quarter, continuing a slide which has led to layoffs, bankruptcies and the closure of several dailies.


Cisco has released a Web security app for iPhone

Cisco releases Web security app for iPhone

Technology / Software

created 16 hours ago | popularity 4.5 / 5 (2) | comments 0

Cisco on Friday announced the release of a free iPhone application for anyone who wants to stay on top of the latest trojans, worms, or other threats marauding on the Internet.