AN ADAPTIVE RISK-BASED AUTHENTICATION FRAMEWORK USING BEHAVIORAL BIOMETRICS AND MACHINE LEARNING FOR CONTINUOUS USER VERIFICATION IN WEB APPLICATIONS

Authors

  • Ekele Olu Department of computer Science (Master in Artificial Intelligence), Miva Open University, Nigeria

Keywords:

Behavioural Biometrics, Continuous Authentication, Machine Learning, Random Forest, Fraud Detection, Risk-Based Authentication, Web Security

Abstract

Authentication remains one of the most important security requirements in modern web applications. Traditional authentication methods, such as passwords and one-time passwords, verify users only during login and provide limited protection against threats such as session hijacking, credential theft, automated bots, and account takeover after authentication. As cyber threats continue to evolve, there is a growing need for intelligent systems that can continuously verify user identity throughout an active session without disrupting the user experience.

This study presents an adaptive risk-based authentication framework that combines behavioural biometrics with machine learning for continuous user verification. The framework captures users' behavioural patterns, including mouse movements, keyboard activity, scrolling behaviour, click frequency, idle time, and session characteristics. These features are converted into numerical data and analysed using a Random Forest model to classify user sessions as either legitimate or suspicious. The model's predictions are then incorporated into a dynamic risk-scoring mechanism that supports adaptive security decisions.

The system was developed using React for the client interface, NestJS for backend services, PostgreSQL with Prisma ORM for data management, and FastAPI for machine learning deployment. The microservice architecture allows efficient communication between behavioural data collection, feature extraction, machine learning prediction, and risk assessment while supporting future improvements without affecting the core system.

The results demonstrate that combining multiple behavioural features provides more accurate contextual information than traditional authentication methods alone. Continuous behavioural monitoring improves fraud detection, reduces false authentication decisions, and enhances web application security through adaptive risk assessment. This study provides a practical framework that bridges the gap between behavioural authentication research and real-world web security applications while establishing a foundation for future research in deep learning, larger behavioural datasets, and real-time adaptive security systems.

Author Biography

  • Ekele Olu, Department of computer Science (Master in Artificial Intelligence), Miva Open University, Nigeria

    Ekele Olu is an MSc student in Artificial Intelligence with a background in Petroleum Engineering and experience in software development, data analytics, machine learning, and cybersecurity. His research interests include artificial intelligence, behavioural biometrics, fraud detection, continuous authentication, autonomous AI agents, knowledge graphs, and AI governance. His current research focuses on developing adaptive, machine learning-based security frameworks that combine behavioural biometrics with risk-based authentication to improve web application security. He is also interested in designing practical AI solutions that address real-world challenges across multiple industries.

References

Acien, A., Morales, A., Vera-Rodriguez, R., & Fierrez, J. (2021). BeCAPTCHA: Behavioral bot detection using mouse and keyboard dynamics. Pattern Recognition, 117, 107975.

Ahmed, A. A. E., & Traore, I. (2020). A new biometric technology based on mouse dynamics. IEEE Transactions on Dependable and Secure Computing, 17(2), 267–278.

Alzubaidi, L., Zhang, J., Humaidi, A. J., Al-Dujaili, A., Duan, Y., Al-Shamma, O., Santamaría, J., Fadhel, M. A., Al-Amidie, M., & Farhan, L. (2021). Review of deep learning: Concepts, CNN architectures, challenges, applications, future directions. Journal of Big Data, 8(1), 53.

Breiman, L. (2001). Random forests. Machine Learning, 45(1), 5–32.

Buczak, A. L., & Guven, E. (2021). A survey of data mining and machine learning methods for cybersecurity intrusion detection. IEEE Communications Surveys & Tutorials, 23(2), 1223–1241.

Eberz, S., Rasmussen, K. B., Lenders, V., & Martinovic, I. (2020). Preventing lunchtime attacks: Fighting insider threats with behavioral biometrics. IEEE Transactions on Dependable and Secure Computing, 17(6), 1174–1187.

Feng, T., Liu, Z., Kwon, K. A., Shi, W., Carbunar, B., Jiang, Y., & Nguyen, N. (2021). Continuous mobile authentication using touchscreen gestures. In Proceedings of the IEEE International Conference on Technologies for Homeland Security (pp. 1–6).

Jain, A. K., Ross, A., & Nandakumar, K. (2021). Introduction to biometrics. Springer.

Javaid, A., & Sengupta, S. (2022). Zero Trust architecture: Concepts, challenges and future directions. IEEE Access, 10, 110735–110756.

Kim, D., & Kim, H. (2022). Continuous authentication using behavioral biometrics in web applications. Computers & Security, 114, 102601.

Liu, Y., Wang, X., & Zhang, L. (2022). Intelligent fraud detection using ensemble machine learning techniques. Expert Systems with Applications, 198, 116743.

Mahbub, U., Komulainen, J., Ferreira, T., Chellappa, R., & Marcel, S. (2021). Continuous authentication: A survey of behavioral biometrics. ACM Computing Surveys, 54(11), 1–36.

National Institute of Standards and Technology. (2020). Digital Identity Guidelines (Special Publication 800-63B). U.S. Department of Commerce.

Rane, N. (2023). Artificial intelligence and machine learning applications in cybersecurity: A review. Sensors, 23(14), 6358.

Sarker, I. H. (2021). Machine learning: Algorithms, real-world applications and research directions. SN Computer Science, 2(3), 160.

Sharma, A., & Mehta, P. (2022). Machine learning approaches for adaptive authentication in cloud computing. Future Generation Computer Systems, 128, 214–226.

Teh, P. S., Zhang, N., Teoh, A. B. J., & Chen, K. (2021). A survey on behavioral biometrics for continuous authentication. ACM Computing Surveys, 54(8), 1–38.

Verma, A., Singh, R., & Gupta, S. (2023). Continuous authentication for secure web applications using behavioral analytics. Journal of Network and Computer Applications, 215, 103634.

Wang, H., Zhao, Y., & Li, X. (2022). Risk-based authentication using behavioral biometrics and machine learning. Knowledge-Based Systems, 247, 108762.

Yampolskiy, R. V., & Govindaraju, V. (2021). Behavioral biometrics: A survey and classification. Pattern Recognition, 118, 108023.

Zhang, C., Li, Y., & Xu, W. (2023). Explainable machine learning for cybersecurity applications: A systematic review. Information Sciences, 627, 497–517.

Zhou, Q., Chen, H., & Wang, J. (2022). Intelligent anomaly detection for web applications using ensemble learning. IEEE Access, 10, 58314–58328.

M. K. Bagwani, S. Dwivedi, V. Kumar, and P. Koshti, "Transmitting malware through QR codes: Risk analysis and a hybrid detection method," International Journal for Multidisciplinary Research, vol. 8, no. 3, pp. 1-25, 2026.

A. M. K. Bagwani and V. K. Tiwari, "Preventing malware spread through QR codes: A detection and analysis approach," Journal of Engineering and Technology Management, vol. 73, pp. 1260-1268, 2024.

A. M. K. Bagwani, V. K. Tiwari, and N. Singh, "Integrating GrapesJS with AWS: Building an educational platform for web development training," An Overview of Literature, Language and Education Research, vol. 10, pp. 106-124, 2025.

M. Bagwani, "Building a cloud-native microservices based web application with GraphQL and Docker," School of Advanced Computing, Sanjeev Agrawal Global Educational University, 2024.

Downloads

Published

2026-08-20

Issue

Section

Original Research Articles

How to Cite

AN ADAPTIVE RISK-BASED AUTHENTICATION FRAMEWORK USING BEHAVIORAL BIOMETRICS AND MACHINE LEARNING FOR CONTINUOUS USER VERIFICATION IN WEB APPLICATIONS. (2026). IJAICET - International Journal of Artificial Intelligence, Cybersecurity and Emerging Technologies, 1(1), 70-79. https://ijaicet.com/index.php/ijaicet/article/view/20