跳到主要导航 跳到搜索 跳到主要内容

Generating look-alike names for security challenges

  • Shuchu Han
  • , Yifan Hu
  • , Steven Skiena
  • , Baris Coskun
  • , Meizhu Liu
  • , Hong Qin
  • , Jaime Perez

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Motivated by the need to automatically generate behavior-based security challenges to improve user authentication for web services, we consider the problem of large-scale construction of realistic-looking names to serve as aliases for real individuals. We aim to use these names to construct security challenges, where users are asked to identify their real contacts among a presented pool of names. We seek these look-alike names to preserve name characteristics like gender, ethnicity, and popularity, while being unlinkable back to the source individual, thereby making the real contacts not easily guessable by attackers. To achive this, we introduce the technique of distributed name embeddings, representing names in a high-dimensional space such that distance between name components reflects the degree of cultural similarity between these strings. We present different approaches to construct name embeddings from contact lists observed at a large web-mail provider, and evaluate their cultural coherence. We demonstrate that name embeddings strongly encode gender and ethnicity, as well as name popularity. We applied this algorithm to generate imitation names in email contact list challenge. Our controlled user study verified that the proposed technique reduced the attacker's success rate to 26.08%, indistinguishable from random guessing, compared to a success rate of 62.16% from previous name generation algorithms. Finally, we use these embeddings to produce an open synthetic name resource of 1 million names for security applications, constructed to respect both cultural coherence and U.S. census name frequencies.

源语言英语
主期刊名AISec 2017 - Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, co-located with CCS 2017
出版商Association for Computing Machinery, Inc
57-67
页数11
ISBN(电子版)9781450352024
DOI
出版状态已出版 - 3 11月 2017
已对外发布
活动10th ACM Workshop on Artificial Intelligence and Security, AISec 2017 - Dallas, 美国
期限: 3 11月 2017 → …

出版系列

姓名AISec 2017 - Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, co-located with CCS 2017

会议

会议10th ACM Workshop on Artificial Intelligence and Security, AISec 2017
国家/地区美国
Dallas
时期3/11/17 → …

指纹

探究 'Generating look-alike names for security challenges' 的科研主题。它们共同构成独一无二的指纹。

引用此