Skip to main content

2024 | OriginalPaper | Buchkapitel

Detecting Web Bots via Mouse Dynamics and Communication Metadata

verfasst von : August See, Tatjana Wingarz, Matz Radloff, Mathias Fischer

Erschienen in: ICT Systems Security and Privacy Protection

Verlag: Springer Nature Switzerland

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

The illegitimate automated usage of Internet services by web robots (bots) is an ongoing problem. While bots increase the cost of operations for service providers and can affect user satisfaction, e.g., in social media and games, the main problem is that some services should only be usable by humans, but their automated usage cannot be prevented easily. Currently, services are protected against bots using visual CAPTCHA systems, the de facto standard. However, they are often annoying for users to solve. Typically, CATPCHAs are combined with heuristics and machine-learning approaches to reduce the number of times a human needs to solve them. These approaches use request data like IP and cookies but also biometric data like mouse movements. Such detection systems are primarily closed source, do not provide any performance evaluation, or have unrealistic assumptions, e.g., that sophisticated bots only move the mouse in straight lines. Therefore we conducted an experiment to evaluate the usefulness of detection techniques based on mouse dynamics, request metadata, and a combination of both. Our findings indicate that biometric data in the form of mouse dynamics performs better than request data for bot detection. Further, training a mouse dynamic classifier benefits from external and not only website-specific mouse dynamics. Our classifier, which differentiates between artificial and human mouse movements, achieves similar results to related work under stricter and more realistic conditions.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat Acien, A., Morales, A., Fierrez, J., Vera-Rodriguez, R.: BeCAPTCHA-mouse: synthetic mouse trajectories and improved bot detection. arXiv:2005.00890 [cs] (2021) Acien, A., Morales, A., Fierrez, J., Vera-Rodriguez, R.: BeCAPTCHA-mouse: synthetic mouse trajectories and improved bot detection. arXiv:​2005.​00890 [cs] (2021)
2.
Zurück zum Zitat Akrout, I., Feriani, A., Akrout, M.: Hacking google reCAPTCHA v3 using reinforcement learning. arXiv preprint arXiv:1903.01003 (2019) Akrout, I., Feriani, A., Akrout, M.: Hacking google reCAPTCHA v3 using reinforcement learning. arXiv preprint arXiv:​1903.​01003 (2019)
3.
Zurück zum Zitat Antal, M., Denes-Fazakas, L.: User verification based on mouse dynamics: a comparison of public data sets. In: 2019 IEEE 13th International Symposium on Applied Computational Intelligence and Informatics, pp. 143–148. IEEE (2019) Antal, M., Denes-Fazakas, L.: User verification based on mouse dynamics: a comparison of public data sets. In: 2019 IEEE 13th International Symposium on Applied Computational Intelligence and Informatics, pp. 143–148. IEEE (2019)
4.
Zurück zum Zitat Antal, M., Egyed-Zsigmond, E.: Intrusion detection using mouse dynamics. IET Biomet. 8(5), 285–294 (2019)CrossRef Antal, M., Egyed-Zsigmond, E.: Intrusion detection using mouse dynamics. IET Biomet. 8(5), 285–294 (2019)CrossRef
6.
Zurück zum Zitat Dee, T., Richardson, I., Tyagi, A.: Continuous transparent mobile device touchscreen soft keyboard biometric authentication. In: 2019 32nd International Conference on VLSI Design and 2019 18th International Conference on Embedded Systems (VLSID), pp. 539–540. IEEE (2019) Dee, T., Richardson, I., Tyagi, A.: Continuous transparent mobile device touchscreen soft keyboard biometric authentication. In: 2019 32nd International Conference on VLSI Design and 2019 18th International Conference on Embedded Systems (VLSID), pp. 539–540. IEEE (2019)
8.
Zurück zum Zitat Gummadi, R., Balakrishnan, H., Maniatis, P., Ratnasamy, S.: Not-a-bot: improving service availability in the face of botnet attacks. In: NSDI, pp. 307–320 (2009) Gummadi, R., Balakrishnan, H., Maniatis, P., Ratnasamy, S.: Not-a-bot: improving service availability in the face of botnet attacks. In: NSDI, pp. 307–320 (2009)
10.
Zurück zum Zitat Iliou, C., Kostoulas, T., Tsikrika, T., Katos, V., Vrochidis, S., Kompatsiaris, I.: Detection of advanced web bots by combining web logs with mouse behavioural biometrics. Digit. Threats: Res. Pract. 2(3), 1–26 (2021)CrossRef Iliou, C., Kostoulas, T., Tsikrika, T., Katos, V., Vrochidis, S., Kompatsiaris, I.: Detection of advanced web bots by combining web logs with mouse behavioural biometrics. Digit. Threats: Res. Pract. 2(3), 1–26 (2021)CrossRef
11.
Zurück zum Zitat Iliou, C., Kostoulas, T., Tsikrika, T., Katos, V., Vrochidis, S., Kompatsiaris, Y.: Towards a framework for detecting advanced web bots. In: Proceedings of the 14th International Conference on Availability, Reliability and Security, ARES 2019. Association for Computing Machinery, New York (2019) Iliou, C., Kostoulas, T., Tsikrika, T., Katos, V., Vrochidis, S., Kompatsiaris, Y.: Towards a framework for detecting advanced web bots. In: Proceedings of the 14th International Conference on Availability, Reliability and Security, ARES 2019. Association for Computing Machinery, New York (2019)
13.
Zurück zum Zitat Jorgensen, Z., Yu, T.: On mouse dynamics as a behavioral biometric for authentication. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, pp. 476–482 (2011) Jorgensen, Z., Yu, T.: On mouse dynamics as a behavioral biometric for authentication. In: Proceedings of the 6th ACM Symposium on Information, Computer and Communications Security, pp. 476–482 (2011)
14.
Zurück zum Zitat Li, X., Azad, B.A., Rahmati, A., Nikiforakis, N.: Good bot, bad bot: characterizing automated browsing activity. In: 2021 IEEE symposium on security and privacy (SP), pp. 1589–1605. IEEE (2021) Li, X., Azad, B.A., Rahmati, A., Nikiforakis, N.: Good bot, bad bot: characterizing automated browsing activity. In: 2021 IEEE symposium on security and privacy (SP), pp. 1589–1605. IEEE (2021)
17.
Zurück zum Zitat Sayed, B., Traoré, I., Woungang, I., Obaidat, M.S.: Biometric authentication using mouse gesture dynamics. IEEE Syst. J. 7(2), 262–274 (2013)CrossRef Sayed, B., Traoré, I., Woungang, I., Obaidat, M.S.: Biometric authentication using mouse gesture dynamics. IEEE Syst. J. 7(2), 262–274 (2013)CrossRef
19.
Zurück zum Zitat Sivakorn, S., Polakis, J., Keromytis, A.D.: I’m not a human: breaking the google recaptcha. Black Hat 14 (2016) Sivakorn, S., Polakis, J., Keromytis, A.D.: I’m not a human: breaking the google recaptcha. Black Hat 14 (2016)
20.
Zurück zum Zitat Suchacka, G., Cabri, A., Rovetta, S., Masulli, F.: Efficient on-the-fly web bot detection. Knowl.-Based Syst. 223, 107074 (2021)CrossRef Suchacka, G., Cabri, A., Rovetta, S., Masulli, F.: Efficient on-the-fly web bot detection. Knowl.-Based Syst. 223, 107074 (2021)CrossRef
Metadaten
Titel
Detecting Web Bots via Mouse Dynamics and Communication Metadata
verfasst von
August See
Tatjana Wingarz
Matz Radloff
Mathias Fischer
Copyright-Jahr
2024
DOI
https://doi.org/10.1007/978-3-031-56326-3_6

Premium Partner