首页> 外文会议>2011 4th Symposium on Configuration Analytics and Automation >Captchæcker: Reconfigurable CAPTCHAs based on automated security and usability analysis
【24h】

Captchæcker: Reconfigurable CAPTCHAs based on automated security and usability analysis

机译:Captchæcker:基于自动安全性和可用性分析的可重新配置的验证码

获取原文

摘要

CAPTCHAs have been deployed ubiquitously by web sites to combat automated malicious programs. Security against web bots and usability to legitimate users are two main goals that have to be simultaneously satisfied when designing a useful CAPTCHA scheme. However, there exists a well-known and intricate trade-off between these goals. So far, balancing this trade-off remains an art rather than a science, as we do not have any automated tools to evaluate the security and usability of CAPTCHAs and then to configure the CAPTCHA generation engine accordingly. In this position paper, we propose a general framework called Captchæcker that aims to solve this configuration problem by automating the security-usability analysis of CAPTCHAs. The proposed framework will allow dynamic reconfiguration of a CAPTCHA scheme after its security-usability goal is changed or its security is compromised due to an attack.
机译:网站已广泛部署了验证码,以打击自动化的恶意程序。设计有用的验证码方案时,必须同时满足两个主要目标,即针对网络漫游器的安全性和对合法用户的可用性。但是,在这些目标之间存在着众所周知的复杂的权衡。到目前为止,平衡取舍仍然是一门艺术,而不是一门科学,因为我们没有任何自动化的工具来评估CAPTCHA的安全性和可用性,然后相应地配置CAPTCHA生成引擎。在本立场文件中,我们提出了一个称为Captchæcker的通用框架,旨在通过自动执行CAPTCHA的安全性-可用性分析来解决此配置问题。提议的框架将允许在更改其安全性-可用性目标或由于攻击而损害其安全性之后对CAPTCHA方案进行动态重新配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号