CRDec 7, 2020

Impact of Network and Host Characteristics on the Keystroke Pattern in Remote Desktop Sessions

arXiv:2012.03577v12 citations
AI Analysis

This research identifies a critical vulnerability for users relying on continuous keystroke authentication in remote desktop environments, as network conditions significantly degrade its effectiveness.

This paper investigates how network conditions and additional host interaction impact keystroke patterns in remote desktop sessions, finding that variations in congestion latency, whether from adjacent traffic or additional remote desktop interactions, substantially affect the Euclidean distance of keystroke patterns. This impact suggests that continuous keystroke authentication is less effective for remote access and more suitable for one-time login.

Authentication based on keystroke dynamics is a convenient biometric approach, easy in use, transparent, and cheap as it does not require a dedicated sensor. Keystroke authentication, as part of multi factor authentication, can be used in remote display access to guarantee the security of use of remote connectivity systems during the access control phase or throughout the session. This paper investigates how network conditions and additional host interaction may impact the behavioural pattern of keystrokes when used in a remote desktop application scenario. We focus on the timing of adjacent keys and investigate this impact by calculating the variations of the Euclidean distance between a reference profile and resulting profiles following such impairments. The experimental results indicate that variations of congestion latency, whether produced by adjacent traffic sources or by additional remote desktop interactions, have a substantive impact on the Euclidian distance, which in turn may affect the effectiveness of the biometric authentication algorithm. Results also indicate that data flows within remote desktop protocol are not prioritized and therefore additional traffic will have a significant impact on the keystroke timings, which renders continuous authentication less effective for remote access and more appropriate for one-time login.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes