Biometric keystroke attribution

Inventors

Tenaglia, Scott D.Morgan, SeanSlater, David

Assignees

Two Six Labs LLC

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-11822636-B1

Patent

Publication Date

2023-11-21

Expiration Date


Abstract

A biometric attribution approach identifies a keyboard actor based on timing between entered keystrokes. Patterns tend to emerge in a timing interval between keystrokes entered by an actor. The keystroke patterns of an actor are analyzed to compute a signature exhibited by the actor. Gathered or intercepted keystroke patterns of an unknown actor are compared to identify a likelihood that typing sessions emanated from a common actor. Keystroke activity of a purported suspect actor can be compared to a database or model of keystroke attributes for determining if the keystroke activity emanated from the same actor as other keystroke sequences. Keystroke patterns rely only on the timing between keystrokes, as key data and upstroke information need not be gathered since the comparisons reply only on keystroke timing deltas.

Core Innovation

The invention assesses an identity of an actor using keystroke interval attributes derived from a plurality of keystrokes received from keyboard input devices operated by actors. The method identifies attributes based on an upstroke or downstroke, and uses timing information indicative of a time delay between each keypress of the depressed keys. The approach focuses on intervals between keystrokes and related timing-derived patterns rather than character values.

The method compares the identified attributes to a second set of attributes based on a second sequence of keystrokes using a feature set comparison and computes, based on a plurality of intervals and an origin, a probability that the keystrokes received from the keyboard and the keystrokes corresponding to the second sequence emanated from a common keyboard actor. The comparison includes generating second sets of attributes by gathering intervals from sequences of keystrokes emanating from an origin.

The invention further specifies generating feature set pairs based on keystroke sequences of a predetermined length, building a model based on the feature set pairs, and transforming timing information into a frequency domain for denoting patterns of timing intervals between depressed keys over a predetermined number of keystrokes. The method also includes generating vectors of comparison sequences representing time intervals from previously pressed keys and comparing the vectors to compute a probability of common origin.

Claims Coverage

The independent claims provide identity assessment of a keyboard actor by deriving keystroke interval attributes, comparing them to a second sequence using feature set comparison or a model, and computing a probability that the two sequences share a common keyboard actor origin. Across the independent claims, the inventive features are timing-interval attribute derivation, interval-based feature set comparison or model comparison, optional removal of upstroke and keystroke data indicative of depressed-key values, fixed-length or predetermined-length representation, and optional frequency-domain transformation or vector-based comparison representations.

Keystroke interval attributes and probability of common keyboard actor origin

Identifying attributes derived from a keystroke interval between each of a plurality of keystrokes received from the keyboard based on an upstroke or downstroke; comparing the identified attributes to a second set of attributes based on a second sequence of keystrokes using a feature set comparison, generating the second set of attributes further comprising gathering a plurality of intervals resulting from a sequence of keystrokes emanating from an origin; and computing, based on the plurality of intervals and the origin, a probability that the plurality of keystrokes received from the keyboard and keystrokes corresponding to the second sequence of keystrokes emanated from a common keyboard actor.

Removal of upstroke information and dataset generation for interval-based actor identity

Identifying attributes derived from a keystroke interval between each of a plurality of keystrokes received from the keyboard; comparing the identified attributes to a second set of attributes based on a second sequence of keystrokes using a feature set comparison, generating the second set of attributes further comprising gathering a plurality of intervals resulting from a sequence of keystrokes emanating from an origin; computing, based on the plurality of intervals and the origin, a probability that the plurality of keystrokes received from the keyboard and keystrokes corresponding to the second sequence of keystrokes emanated from a common keyboard actor, further comprising removing upstroke information to generate a sequence of intervals, each interval in the sequence of intervals defined by a keystroke of a depressed key; removing keystroke data information indicative of a value associated with the depressed key; and generating a dataset of the intervals based on timing information between keystrokes in each sequence of keystrokes and the origin of the sequence of keystrokes.

Frequency-domain timing patterns and feature set pairs with model-based comparison

Identifying attributes derived from a keystroke interval between each of a plurality of keystrokes received from the keyboard, the derived attributes including timing information indicative of a time delay between each keypress of the depressed keys, further comprising generating a plurality of feature set pairs, the feature set pairs based on keystroke sequences of a predetermined length; and building a model based on the feature set pairs; comparing the identified attributes to a second set of attributes based on a second sequence of keystrokes using the model, generating the second set of attributes further comprising gathering a plurality of intervals resulting from a sequence of keystrokes emanating from an origin; transforming the timing information into a frequency domain for denoting patterns of timing intervals between depressed keys over a predetermined number of keystrokes; comparing the patterns of timing intervals resulting from a plurality of typing sessions for computing a probability that an origin of a first typing session matches an origin of a second typing session of the plurality of typing sessions; and computing, based on the plurality of intervals and the respective origin, a probability that the plurality of keystrokes received from the keyboard and keystrokes corresponding to the second sequence of keystrokes emanated from a common keyboard actor.

Vector-based comparison of time-interval sequences for probability of common origin

Identifying attributes derived from a keystroke interval between each of a plurality of keystrokes received from the keyboard; comparing the identified attributes to a second set of attributes based on a second sequence of keystrokes, comparing the identified attributes further comprising demarcating a comparison sequence of a predetermined number of keystrokes for the identified attributes and the second set of attributes; generating a respective vector of the comparison sequence having a sequence of elements such that each successive element in the sequence of elements represents a time interval from a previously pressed key; performing a comparison of the respective vectors based on the identified attributes and the second set of attributes; and computing, based on the plurality of intervals and the origin, a probability that the plurality of keystrokes received from the keyboard and keystrokes corresponding to the second sequence of keystrokes emanated from a common keyboard actor.

Computer program implementing interval dataset generation with removal of upstroke and keystroke data

Identifying attributes derived from a keystroke interval between each of a plurality of keystrokes received from the keyboard; comparing the identified attributes to a second set of attributes based on a second sequence of keystrokes using a feature set comparison, further comprising generating the second set of attributes further comprises gathering a plurality of typing sessions, each typing session in the plurality of typing sessions resulting from a sequence of keystrokes emanating from an origin; removing upstroke information to generate a sequence of intervals between each keystroke of a depressed key; removing keystroke data information indicative of a value associated with the depressed key for the upstroke and downstroke; and generating a dataset of the intervals based on timing information between keystrokes in each sequence of keystrokes and the origin of the sequence of keystrokes; and computing, based on the plurality of intervals and the origin, a probability that the plurality of keystrokes received from the keyboard and keystrokes corresponding to the second sequence of keystrokes emanated from a common keyboard actor.

Across the independent claims, the core claim coverage is the derivation of keystroke interval attributes, feature set comparison or model-based comparison against attributes from a second keystroke sequence, and computation of a probability that both sequences emanated from a common keyboard actor origin. Additional independent-claim-specific aspects include removing upstroke information and keystroke-data values indicative of depressed-key values, generating frequency-domain timing patterns using feature set pairs and a model, and using comparison vectors of time-interval sequences.

Stated Advantages

Attribution of sessions using encrypted remote console sessions by analyzing keystroke timing intervals.

Does not require character values and dwell time as characterized as conventional keyboard stylometry.

Attributes across multiple cyber intrusions via typing stylometry.

Documented Applications

Using biometric keystroke attribution to identify/link keyboard actors by analyzing keystroke timing deltas from encrypted remote console sessions where keystroke-indicative character data is encrypted.

Attributing typing sessions across multiple cyber intrusions using typing stylometry to compute probability that sessions share a common keyboard actor.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.