Security

Behavioral biometrics, explained

A person typing on a computer keyboard

Photo: Ilya Pavlov on Unsplash

“Behavioural biometrics” sounds like a surveillance product. In a checkout it means something much narrower and much duller: how the form was filled in, not who filled it in. That distinction is the whole subject.

The signal

These signals are one input to WooFraudGuard’s order score. Someone buying something with their own card behaves differently from someone working through a list of stolen ones. Not in ways you would notice watching over their shoulder, but in ways a checkout form can measure:

  • Typing versus pasting. People type their own address, mostly from memory, with the pauses and corrections that implies. Card details worked through in bulk get pasted, field by field.
  • Time on form. A genuine checkout has human hesitation in it. A scripted one is often implausibly fast.
  • Typing speed on the email field. Measured in characters per second. People top out somewhere around ten to fifteen; well beyond that, nobody typed it.
  • Autofill. Which fields the browser filled in, as against the ones a person actually touched.
  • Mouse movement. An entropy score over the pointer’s changes of direction. Bots draw straight lines, or no lines at all.
  • Tab switches and submission attempts. How often the shopper left the page mid-checkout, and how many times they tried to submit it.

None of these identifies a person. They describe an interaction. That is a deliberate design choice, not a limitation we are apologising for.

What is measured, and what is not

This is the part worth being precise about, because the category has a bad reputation it partly earned.

What is recorded is a small set of aggregate numbers about the interaction — roughly how long the form took, whether each field was pasted or autofilled, how fast the email address was typed, how often the tab lost focus. What is not recorded is keystroke content. Your customer’s name, address and card number are not captured as typing data, and there is no profile that follows anyone between sites. The signals exist for the duration of a checkout and are summarised into a handful of values attached to that order.

If you are writing a privacy policy, this is the honest description: interaction metadata about a single checkout, stored on your own site, used to score that order.

What it is good at

Behavioural signals are strongest against exactly the case where traditional signals are weakest: a fraudster with good stolen data. If someone has the real cardholder’s name, address, and card number, then address checks pass, the email looks plausible, and the order looks clean. What they cannot easily fake is filling the form in the way the actual owner of that information would.

They are also cheap. There is no external service to call, no per-check fee, and no added latency at checkout.

What it is not good at

Used alone, these signals are weak and easy to get wrong:

  • Password managers paste everything. A privacy-conscious customer autofilling their details looks, superficially, like automation. This is the single most common false positive.
  • Accessibility tools change interaction patterns. Screen readers, voice input and switch devices all produce input that is nothing like a sighted user typing.
  • Mobile is different. Autofill on a phone is the norm, not the exception.
  • It is defeatable. A determined attacker can simulate human timing. The signal raises the cost of bulk fraud; it does not stop targeted fraud.

This is why behavioural signals should be a moderate contributor to a score and never a rejection on their own. An order should not be cancelled because someone used a password manager. Combined with a billing mismatch and a fresh email domain, the same signal is genuinely informative.

How to weight it

Treat it as corroboration, and weight it accordingly. On its own it should not move an order past your review threshold; alongside two or three other signals it reasonably should. If you sell to a technical audience — who are more likely to use password managers — weight it lower still.

As with every rule, the useful check is retrospective: look at orders that actually resulted in a dispute and see whether this signal was present. If it was not, it is not earning its weight on your store, and it should come down.

UC
Uche
CHADA team

Build on tools you can trust

Browse the CHADA catalogue — premium WordPress plugins with honest licensing.

Browse plugins