Assessing Vulnerabilities of Biometric Readers Using an Applied Defeat Evaluation Methodology

نویسنده

  • David J. Brooks
چکیده

Access control systems using biometric identification readers are becoming common within critical infrastructure and other high security applications. There is a perception that biometric, due to their ability to identify and validate the user, are more secure. However, biometric systems are vulnerable to many categories of attack vectors and there has been restricted research into such defeat vulnerabilities. This study expands on a past article (Brooks, 2009) that presented a defeat evaluation methodology applied to high-security biometric readers. The defeat methodology is represented, but applied to both fingerprint and back-of-hand biometric readers. Defeat evaluation included both physical and technical integrity testing, considering zero-effort to adversarial complex attacks. In addition, the evaluation considered the whole device and not just the biometric extraction and storage device. The study found a number of common vulnerabilities in the various types of biometric readers. Vulnerabilities included the ability to spoof optical readers with another person’s extracted print, use of inanimate objects to enrol and validate, defeat of live detection and the ability to by-pass the biometric reader. Optical sensors appeared the least secure, with capacitive the most secure. An awareness of the vulnerabilities and limitations of biometric readers need to be propagated, as such readers should not be considered high-security by default. As this study demonstrated, most of the readers had some inherent vulnerability that was not difficult to exploit, in particular, from an insider’s perspective.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Proceedings of the 2 nd Australian Security and Intelligence Conference

Biometric access control systems are becoming more common and may be considered high-security, due to their ability to identify and validate that the person is who they purport to be. Therefore, such biometric systems are often installed into critical infrastructure facilities as a means to gain high security protection. To date, there has been considerable research into the effectiveness of bi...

متن کامل

Towards the Security Evaluation of Biometric Authentication Systems

Despite the obvious advantages of biometric authentication systems over traditional security ones (based on tokens or passwords), they are vulnerable to attacks which may considerably decrease their security. In order to contribute in resolving such problematic, we propose a modality-independent evaluation methodology for the security evaluation of biometric systems. It is based on the use of a...

متن کامل

Intelligent buildings: an investigation into current and emerging security vulnerabilities in automated building systems using an applied defeat methodology

Intelligent Buildings (IB) have become increasing popular during the past decade, driven through the need to reduce energy, have more reactive and safer buildings, and increase productivity. IB integrate many systems that were in the past isolated from each other, including fire and life safety, HVAC, lighting, security, etc. Facilities contain commercial-in-confidence material and other valued...

متن کامل

Quantitative Security Evaluation of a Multi-biometric Authentication System

Biometric authentication systems verify the identity of users by relying on their distinctive traits, like fingerprint, face, iris, signature, voice, etc. Biometrics is commonly perceived as a strong authentication method; in practice several well-known vulnerabilities exist, and security aspects should be carefully considered, especially when it is adopted to secure the access to applications ...

متن کامل

A Trusted Biometric System

This technical report describes a method for biometric identification based user authentication in distributed environments, which makes use of Trusted Platforms combined with Smart Cards and Trusted Biometric Readers for providing a trusted biometric system. With this authentication method, a user can establish a trust relationship with a Biometric Reader (via integrity checking), and the user...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010