Back to results

University of Pretoria

Continuous authentication on android mobile devices

Abstract

dc:description.abstract

Initial authentication methods, such as passwords and PINs, secure access to an Android mobile device only at login, leaving active sessions vulnerable to unauthorised access. With over 3.9 billion Android mobile users worldwide and the widespread use of ultra-short messages in applications like WhatsApp, Telegram, and email, this security gap poses a significant risk to the confidentiality, integrity, and availability of sensitive information. Recent breaches, including the 2025 ByHeist and Microsoft Exchange compromises, highlight how attackers exploit active sessions through token theft and session hijacking to access ultra-short message conversations after bypassing initial authentication.This study investigates whether ultra-short messages of 30 characters or fewer can provide sufficient behavioural data for reliable continuous authentication on Android mobile devices. A continuous authentication system (CAS) combining typing speed measurements and stylometric analysis was developed and evaluated through five systematic experiments. Data was collected from a total of 41 participants (with 34 left after cleaning) using a custom-made React Native mobile application. The application simultaneously captured typing speed and text content as participants responded to chat questions.This research addressed four sub-questions evaluating: (1) typing speed discriminative power, (2) stylometry discriminative power, (3) the benefits of combining typing speed and stylometry, and (4) the optimal window size and user group configurations. Results demonstrated that typing speed alone achieved a strong discriminative power with F-statistic = 4.26, but with high within-user variability, with a coefficient of variation (CV) between 54.5% and 74.8%. At the same time, stylometry showed moderate discriminative power with F-statistic = 3.64 but with enhanced stability, with CV between 24.8% to 34.8%. The combined approach using adaptive weighting achieved F-statistic = 4.08, successfully balancing discriminative power strength with behavioural consistency.Optimal configurations with five and ten participants and 25-character windows achieved a True Authentication Rate (TAR) of 80% and a True Negative Rate (TNR) ranging from 57.8% to 65%. However, scaling to 34 participants revealed a security-usability trade-off, with TAR degrading by 19.1% while TNR degraded by 2.5%.This research contributes to mobile security by demonstrating that ultra-short messages of 25 to 30 characters can serve as a viable data source for continuous authentication, providing a supplementary layer of protection that complements rather than replace initial authentication methods. The findings reveal that continuous authentication is feasible for small user groups in instant messaging contexts. However, the 35% False Positive Rate (FPR) indicates that the approach proposed in this study should be deployed as part of a multi-factor continuous authentication strategy, rather than as a standalone security measure.

Degree

thesis:*
Grantor dc:publisher
University of Pretoria
Year dc:date.issued
2025

Author and committee

dc:creator, dc:contributor.*
Advisor dc:contributor.advisor
  • Eloff, Jan H.P.

Subjects

dc:subject × 8

Rights

dc:rights
Statement dc:rights
  • © 2024 University of Pretoria. All rights reserved. The copyright in this work vests in the University of Pretoria. No part of this work may be reproduced or transmitted in any form or by any means, without the prior written permission of the University of Pretoria.
Language dc:language.iso
en

Identifiers

dc:identifier.*
Dc Identifier Other
A2026
OAI identifier oai:identifier
oai:repository.up.ac.za:2263/108721

Chain of custody

source
Harvested from
University of Pretoria
Base URL
repository.up.ac.za/server/oai/request
Last updated
2026-07-24
Source record
OAI-PMH GetRecord
citation

Continuous authentication on android mobile devices. University of Pretoria, 2025. http://hdl.handle.net/2263/108721