Addressing Unique Vulnerabilities in Biometric Technologies
Dr Ted Dunstone CEO BixeLab
ted@bixelab.com
Addressing Unique Vulnerabilities in Biometric Technologies
Dr Ted Dunstone CEO BixeLab
ted@bixelab.com
CVSS impact metrics give equal weight to confidentiality, integrity, and availability, overlooking the unique risk priorities of organizations and the true impact a vulnerability might have,
analysis suggests that around 10% of vulnerabilities are potentially being underrated
JPMorganChase
This relies on standard metrics that do not fully capture the unique aspects of biometric vulnerabilities, such as spoofing attacks or demographic biases
Bias Impact: Evaluate vulnerabilities' effects on specific demographic groups, leading to unequal security.
Utilise Biometric-Specific Metrics:
Enhance Environmental Metrics:
Standardize Reporting of Biometric Vulnerabilities:
ICAO Standard Photo Taken
Biometric Data
Store
Biometric Data
Store
Score
0 (not match)
1 (best match)
0.8
Score
0 (not match)
1 (best match)
0.6
Score
0 (not match)
1 (best match)
Score
0 (not match)
1 (best match)
0.5
Score
-100 (not match)
100 (best match)
Score
Frequency
Score
Frequency
Score
Frequency
Score
Frequency
Score
Frequency
Score
Frequency
Score
Frequency
Score
Frequency
Threshold
Score
Frequency
Threshold
Score
Frequency
Threshold
❌
Score
Frequency
✅
❌
Threshold
stored
reference
stored
reference
probe
reference
✅
stored
reference
probe
reference
comparison
Threshold
stored
reference
probe
reference
comparison
Threshold
❌
stored
reference
probe
reference
comparison
stored
reference
probe
reference
comparison
stored
reference
stored
reference
probe
reference
comparison
stored
reference
comparison
stored
reference
probe
reference
comparison
stored
reference
comparison
stored
reference
probe
reference
comparison
stored
reference
comparison
✅
❌
Raw Biometric
Template
Quality
Transaction
Biographics
Raw Biometric
Template
Quality
Transaction
Biographics
1. Attack Vector (AV): Physical (P)
2. Attack Complexity (AC): Low (L)
3. Privileges Required (PR): None (N)
4. User Interaction (UI): Required (R)
5. Scope (S): Unchanged (U)
6. Confidentiality Impact (C): None (N)
7. Integrity Impact (I): High (H)
8. Availability Impact (A): None (N)
Risk Assessment:
System Design:
Policy Development:
Training and Awareness:
Commercial-in-Confidence, © 2024 BixeLab Pty Ltd
The Biometric Quality Assessment Tool (BQAT) is an open-source quality assessment tool for analyzing and generating biometric sample quality to international standards.
Supported biometric modalities include:
ID: 1232324
Commercial-in-Confidence, © 2024 BixeLab Pty Ltd