...
首页> 外文期刊>Security and Communications Networks >The design and implementation of a secure CAPTCHA against man-in-the-middle attacks
【24h】

The design and implementation of a secure CAPTCHA against man-in-the-middle attacks

机译:防止中间人攻击的安全验证码的设计和实现

获取原文
获取原文并翻译 | 示例
   

获取外文期刊封面封底 >>

       

摘要

In this paper, we propose a novel security protocol for the implementation of CAPTCHA tests that feature advance mechanisms against man-in-the-middle (MITM, for short) attacks. This type of attack is fulfilled by a malicious entity, the MITM, that leverages on unaware users to mass-solve CAPTCHA tests shielding the access to a service. The protocol that we propose uses collision-resistant hash functions modeled as random oracles to guarantee that the solution to a CAPTCHA test solved by an end user is valid only for the server to which the user is connected to. This will prevent MITM attacks because the user is not directly connected to the server. We developed a reference implementation for our protocol that has a low impact and is easy to use, featuring a software plug-in running in the Firefox web browser, on the client side, and a Java servlet-based application, on the server side. Copyright (c) 2013 John Wiley & Sons, Ltd.
机译:在本文中,我们提出了一种用于实施CAPTCHA测试的新颖安全协议,该协议具有针对中间人(MITM)的先进机制。这类攻击由恶意实体MITM来实现,该恶意实体利用不知情的用户来大规模解决CAPTCHA测试,从而屏蔽了对服务的访问。我们建议的协议使用建模为随机预言的抗冲突哈希函数,以确保最终用户解决的CAPTCHA测试解决方案仅对与用户连接的服务器有效。这将防止MITM攻击,因为用户没有直接连接到服务器。我们为该协议开发了一种参考实现,该协议的影响小且易于使用,其功能是在客户端的Firefox Web浏览器中运行一个软件插件,在服务器端的一个基于Java Servlet的应用程序。版权所有(c)2013 John Wiley&Sons,Ltd.

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号