Biometric recognition and authentication systems
Pages
Page 4 of 13
How biometrics are attacked
Introduction
In this section we look at the weaknesses and error types to which all modalities are vulnerable.
We examine the points at which a biometric system can be attacked and how these attacks are likely to be implemented. Where relevant, we also consider the data targeted, examining how systematic weaknesses can be exploited to achieve compromise.
This information should help you query suppliers about their protective measures, and to plan your own system defences effectively. As a minimum, you should be aware of any risks which your system carries.
Attack types
In this document we are focusing on those vulnerabilities specific to biometrics.
Many of these reported vulnerabilities involve the presentation of artefacts at the sensor, so are known as presentation attacks. However, a broader range of attacks is possible.
Presentation attacks
Presentation attacks involve an impostor using an artefact of some kind to mimic an individual who has been enrolled in the system.
For example: If a fingerprint of the enrolled individual can be captured, this could be used to make a matching artefact. For face recognition, a portrait photo of the target might easily be taken covertly and used to create an artefact.
With the co-operation of the individual to be impersonated, it can be relatively simple for the impostor to obtain details of the biometric characteristic to be mimicked. Without such cooperation, obtaining biometric characteristics with the necessary level of detail may be more challenging. Exactly how challenging depends on the biometric modality employed.
Covert imaging is much harder for iris or vein recognition, where specialised cameras and close proximity to the target are needed. The nature of the particular biometric modality will also influence the difficulty of making a suitable artefact to present to the biometric system.
Sensor output interception
An attacker may seek to modify or intercept the data output from the sensor. A previously captured sample might be replayed, or a captured biometric sample could be substituted with biometric data of a different individual at enrolment.
Intercepted data might be used by an attacker to obtain the biometric characteristics of an enrolled individual for use in future attacks. Built-in security features supporting secure capture and processing of biometric data on a mobile device can be used to mitigate against sensor output interception.
Reference and database-related vulnerabilities
An attacker may target data during transmission, or in storage by the biometric system. For example, a biometric reference in the enrolment database could be modified to include the biometric features of an impostor.
In implementations where the biometric data is stored on a device held by the individual, such as a mobile phone, passport or ID card, an attacker with possession of the device would have unfettered access to the biometric data unless it is protected by built-in security features. One approach to protect biometric data is to hold it centrally, with secure transmission and storage.
Integrity of enrolment
There is a possibility that the enrolment process could be subverted, allowing the acceptance of inappropriate enrolment data. For example if an artefact is enrolled in the system, then an attacker might later be able to use the same artefact to be recognised.
Alternatively, if an enrolment record contains biometric data of two individuals (for example the right hand is properly enrolled, but the enrolled left hand is that of another individual, or if a face enrolment uses an image which morphs together photographs of two individuals) this may allow one individual to impersonate the other. Therefore, it is important that the enrolment process is designed to address the possibility of subversion.
System attacks
Attacks against the underlying IT on which the biometric system runs are certainly feasible and must be considered in cases where the assets being protected are of significant value and where the attackers are relatively sophisticated.
Generally, the mitigation of such attacks relies on traditional IT security methods which are not specific to biometric systems. However, storing a database of biometric data creates a significant volume of PII which must be protected, as such information is highly prized by attackers.
Denial of service attacks
All systems are vulnerable to denial of service attacks. In the case of a biometric system, this will divert subjects to the exception handling system. It is therefore important that this fallback system is no less secure than the biometric system.
Insider threat
All security systems are vulnerable to an attack by a trusted system administrator or operator. Due to the level of access and trust held by such people, insider attacks on a biometric system can take any of the forms outlined above.
Next steps: risks and reassurances
This is not an exhaustive list of the attacks possible against biometric systems. The goal here is to demonstrate that biometric systems, like all security systems, have vulnerabilities. The industry is actively addressing these issues, but vulnerabilities remain. In light of this, you will need to assess the motivations and capabilities of prospective attackers and any consequent risks.
Suppliers may provide countermeasures for some attacks, thereby making their products more secure. You should ask a vendor what protections are provided, particularly for any attacks you have deemed possible in your circumstances.
You should also establish whether a detailed security analysis of the product has been carried out, by whom and to what level - from private sector organisations through to high assurance evaluations from nationally-accredited bodies.


