An image replay attack is the use of a picture to fool an authentication method.

Image replay attacks are most commonly used by an attacker trying to gain entry to a system protected by less-than-secure biometric authentication technology implementations. The method has been used successfully against low-end fingerscanners, iris scanners and facial recognition systems.

In the simplest cases, image replay attacks involve a printed image of the subject used for authentication. An attacker might, for example, present a picture of an authorized user to a facial recognition system. Extra measures can be implemented in facial recognition and iris scans to foil printed or static images, however; such measures include requiring the user to wink, blink or speak.

More sophisticated image replay attack methods may involve recorded video and audio playback to defeat these measures. Methods of defeating these attacks exist as well, however. Video and audio are typically out of sync to a detectable degree when played back from a file. Security algorithms have been created to detect the discrepancy and prevent these attacks.

Making biometric authentication methods secure from image replay attacks can’t rely on the methods used to detect data replay attacks. (The opposite is also true.) When security is important, it is advisable for administrators to be aware of both attack methods and counter measures.

Lascia un commento

Il tuo indirizzo email non sarà pubblicato. I campi obbligatori sono contrassegnati *

Explore More

Password manager

Secondo Trend Micro, i password manager (https://www.cybersecurity360.it/cultura-cyber/password-manager-cosa-sono-quali-sono-i-migliori-come-usarli-e-perche/) sono il nuovo obiettivo dell’info-stealing ViperSoftX, per rubare dati e credenziali (https://www.cybersecurity360.it/nuove-minacce/password-compromesse-ecco-come-scoprire-se-i-nostri-account-sono-al-sicuro/) nelle estensioni dei browser.

Dark web non più anonimo: scoperto un modo per rilevare gli IP address dei server Tor

Tor fornisce anonimato ed è resistente all’identificazione e al tracciamento. Ma una recente scoperta ha rivelato un nuovo modo per comprendere il vero indirizzo IP di un servizio utilizzando un’intestazione HTTP nota

Cos’è lo Zero-Trust? – In che modo protegge la tua azienda dagli attacchi informatici?

By Cyber Writes Team – 29 maggio 2023 Le tradizionali misure di sicurezza basate sul perimetro devono essere aggiornate in un ecosistema digitale sempre più interconnesso in cui la frequenza