Abstract
dc:description.abstractInitial authentication methods, such as passwords and PINs, secure access to an Android mobile device only at login, leaving active sessions vulnerable to unauthorised access. With over 3.9 billion Android mobile users worldwide and the widespread use of ultra-short messages in applications like WhatsApp, Telegram, and email, this security gap poses a significant risk to the confidentiality, integrity, and availability of sensitive information. Recent breaches, including the 2025 ByHeist and Microsoft Exchange compromises, highlight how attackers exploit active sessions through token theft and session hijacking to access ultra-short message conversations after bypassing initial authentication.This study investigates whether ultra-short messages of 30 characters or fewer can provide sufficient behavioural data for reliable continuous authentication on Android mobile devices. A continuous authentication system (CAS) combining typing speed measurements and stylometric analysis was developed and evaluated through five systematic experiments. Data was collected from a total of 41 participants (with 34 left after cleaning) using a custom-made React Native mobile application. The application simultaneously captured typing speed and text content as participants responded to chat questions.This research addressed four sub-questions evaluating: (1) typing speed discriminative power, (2) stylometry discriminative power, (3) the benefits of combining typing speed and stylometry, and (4) the optimal window size and user group configurations. Results demonstrated that typing speed alone achieved a strong discriminative power with F-statistic = 4.26, but with high within-user variability, with a coefficient of variation (CV) between 54.5% and 74.8%. At the same time, stylometry showed moderate discriminative power with F-statistic = 3.64 but with enhanced stability, with CV between 24.8% to 34.8%. The combined approach using adaptive weighting achieved F-statistic = 4.08, successfully balancing discriminative power strength with behavioural consistency.Optimal configurations with five and ten participants and 25-character windows achieved a True Authentication Rate (TAR) of 80% and a True Negative Rate (TNR) ranging from 57.8% to 65%. However, scaling to 34 participants revealed a security-usability trade-off, with TAR degrading by 19.1% while TNR degraded by 2.5%.This research contributes to mobile security by demonstrating that ultra-short messages of 25 to 30 characters can serve as a viable data source for continuous authentication, providing a supplementary layer of protection that complements rather than replace initial authentication methods. The findings reveal that continuous authentication is feasible for small user groups in instant messaging contexts. However, the 35% False Positive Rate (FPR) indicates that the approach proposed in this study should be deployed as part of a multi-factor continuous authentication strategy, rather than as a standalone security measure.
Degree
thesis:*- Grantor dc:publisher
- University of Pretoria
- Year dc:date.issued
- 2025
Author and committee
dc:creator, dc:contributor.*- Advisor dc:contributor.advisor
-
- Eloff, Jan H.P.
Subjects
dc:subject × 8Rights
dc:rights- Statement dc:rights
-
- © 2024 University of Pretoria. All rights reserved. The copyright in this work vests in the University of Pretoria. No part of this work may be reproduced or transmitted in any form or by any means, without the prior written permission of the University of Pretoria.
- Language dc:language.iso
- en
Identifiers
dc:identifier.*- Dc Identifier Other
- A2026
- OAI identifier oai:identifier
- oai:repository.up.ac.za:2263/108721