Computer scientists work to strengthen online security

November 9, 2009

If you forget your password when logging into an e-mail or online shopping Web site, the site will likely ask you a security question: What is your mother's maiden name? Where were you born?

The trouble is that such questions are not very secure. More people than you may think will know your answers. And if they don't, it might not be hard to search for it online or even make a lucky guess.

But Rutgers computer scientists are testing a new tactic that could be both easier and more secure.

"We call them activity-based personal questions," said Danfeng Yao, assistant professor of computer science in the Rutgers School of Arts and Sciences. "Sites could ask you, 'When was the last time you sent an e-mail?' Or, 'What did you do yesterday at noon?'"

Yao and her students have been testing how resistant these activity questions are to "attack," - computer security lingo for when an intruder answers them correctly and gains access to personal information such as e-mails or to do online shopping or banking.

Early studies suggest that questions about recent activities are easy for legitimate users to answer but harder for potential intruders to find or guess, Yao said.

"We want the question to be dynamic," she said. "The questions you get today will be different from the ones you would get tomorrow."

Rutgers doctoral student Huijun Xiong and visiting undergraduate student Anitra Babic are presenting the group's preliminary results in a workshop at this week's Association for Computing Machinery Conference on Computer and Communications Security. Babic is a senior at Chestnut Hill College in Philadelphia and participated in a summer research program at Rutgers.

Yao said she gave four students in her lab a list of questions related to network activities, physical activities and opinion questions, and then told them to "attack" each other.

"We found that questions related to time are more robust than others. Many guessed the answer to the question, 'Who was the last person you sent e-mail to?' But fewer were able to guess, 'What time did you send your last e-mail?'"

Yao explains that it should not be difficult for an online service provider to formulate these kinds of security questions by looking at its users' e-mail, calendar activities or previous transactions. Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy.

Yao is proposing further studies to determine the practicality of the new approach and the best way to implement it.

Source: Rutgers University (news : web)


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - not rated yet

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • paulthebassguy - Nov 09, 2009
    • Rank: not rated yet
    But I can't remember exactly when I sent my last email?! I think that this is a nice concept but it will fail due to the actual practicality of it.

    Also "Computers would have use natural language processing tools to synthesize understandable questions and analyze the answers for accuracy" - NLP algorithms are notorious for wording incomprehensible sentences and not understanding normal sentences properly when there is the slightest amount of ambiguity.

November 9, 2009 all stories

Comments: 1

not rated yet
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Study finds you get what you pay for with online Q & A sites
    created Apr 09, 2008 | popularity not rated yet | comments 0
  • Users of Yahoo Answers seek advice, opinion, expertise
    created Apr 22, 2008 | popularity not rated yet | comments 0
  • Yahoo! launches Web answering site
    created Dec 08, 2005 | popularity not rated yet | comments 0
  • Twitter hacked by old technique -- again
    created Jul 15, 2009 | popularity not rated yet | comments 0
  • Rational or Random? Model Shows How People Send E-Mails
    created Nov 19, 2008 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Buying a Wii - what do I want?
    created Nov 29, 2009
  • iTouch apps
    created Nov 27, 2009
  • Sixth sense technology
    created Nov 26, 2009
  • kindle e-reader and scientific papers
    created Nov 24, 2009
  • More from Physics Forums - Computing & Technology

Other News

Google said it will let publishers set a limit on the number of articles people can read for free

Google to let publishers limit free website access

Technology / Internet

created 1hour ago | popularity 5 / 5 (1) | comments 2

Google on Tuesday said it will let publishers set a limit on the number of articles people can read for free through its search engine.


New York State Attorney General Andrew Cuomo

Facebook, MySpace ban New York sex offenders

Technology / Internet

created 1hour ago | popularity not rated yet | comments 0

Facebook and MySpace have closed the accounts of 3,533 convicted sex offenders in New York state under a law combating online predators, officials said Tuesday.


'Outbreaks Near Me' app now available for Android mobile phones

Technology / Software

created 1hour ago | popularity not rated yet | comments 0

(PhysOrg.com) -- "Outbreaks Near Me," an up-to-the-minute disease-tracking system released as an iPhone application in September, is now available for use on Android mobile phones, greatly increasing the number of people ...


Rupert Murdoch

Murdoch: Media must get readers to pay for online

Technology / Internet

created 4 hours ago | popularity not rated yet | comments 5

(AP) -- Media companies wishing to thrive in the digital age need to persuade consumers to pay for news online by providing compelling information in any form they want, News Corp. Chairman and CEO Rupert ...


Security ID cards with built-in holograms

Security ID cards with built-in holograms (w/ Video)

Technology / Hi Tech

created 9 hours ago | popularity 4.7 / 5 (3) | comments 0

(PhysOrg.com) -- Plastic cards with security features are ubiquitous these days, having a wide variety of uses such as credit cards, employee cards, licenses, and so on. Many have holographic images, but they ...