Independent Biometrics Expertise

Home - About IBG - Contact IBG
 Services and Solutions > Biometrics Testing and Certification > Biometrics Vulnerability and Penetration Testing

Biometrics Vulnerability and Penetration Testing

In addition to our accuracy- and enrollment-focused Comparative Biometric Testing, International Biometric Group performs custom Vulnerability and Penetration Testing of biometric devices and systems. IBG evaluates resistance to spoof attacks, replay attacks, communication attacks, and other attempts to defeat or circumvent biometric systems.

IBG's Vulnerability and Penetration Testing details the susceptibility of biometric systems to typical attacks, assesses the level of effort required to perform successful attacks, and maps system vulnerabilities to typical applications to determine if the risk of attack is real or academic.

This testing incorporates both single-device tests and comparative tests, and is customized to address the particular vulnerabilities of each technology. Among the areas addressed are the following:

Device-Level

  • Human interface-level penetration and liveness emulation vulnerability. How resistant is the device to spoofing?

  • Device penetration vulnerability. How resistant is the device to attacks on the reader or scanner itself designed to replicate or manipulate biometric data?

  • Wire and transmission penetration vulnerability. How resistant is the system to attacks on cables, wires, and other communications means that lend themselves to data intercept and insertion?

System-Level

  • Algorithm- and template-level vulnerability. How resistant is the system to attacks on biometric data and matching processes, including reverse-engineer and database attacks?

  • Administrative and account vulnerability. How resistant is the system to administrator-level and account-level deletion or alteration of stored data?

  • System software vulnerability. How resistant is the system to attacks on drivers and other software components that enable the biometric system?

Contact IBG to learn more about how our customized testing and evaluation services can mitigate the risks involved in large-scale deployments, improve your technology's competitive position in the biometric industry, and facilitate decisions on investment, partnership, or acquisition.

Copyright © 2003-2007 International Biometric Group