首页> 外文会议>International conference on information systems security >Web Services Based Attacks against Image CAPTCHAs
【24h】

Web Services Based Attacks against Image CAPTCHAs

机译:基于Web服务的针对图像验证码的攻击

获取原文

摘要

CAPTCHAs provide protection from automated robot attacks against online forms and services. Image recognition CAPTCHAs, which require users to perform an image recognition task, have been proposed as a more robust alternative to character recognition CAPTCHAs. However, in recent years, a number of web services that deal with content based image retrieval and analysis have been developed and released for public consumption. These web services can be used in completely unexpected ways to attack image CAPTCHAs. Specifically, in this paper, we consider three specific kinds of web services: 1) Reverse Image Search (RIS), 2) Image Similarity Search (ISS), and 3) Automatic Linguistic Annotation (ALA). We show how the functionality of these image based web services, used in conjunction with regular expressions, keyword ontologies and some statistical analysis/inference, can pose a dangerous attack that easily bypasses the hard AI problem used in challenges for typical image CAPTCHAs. We also discuss effective defensive measures that can be utilized to make CAPTCHAs more resistant to the attack vectors these web services provide.
机译:CAPTCHA提供了针对在线表单和服务的自动机器人攻击保护。已经提出了要求用户执行图像识别任务的图像识别验证码,作为字符识别验证码的更健壮的替代方案。但是,近年来,已经开发并发布了许多处理基于内容的图像检索和分析的Web服务,以供公众使用。这些Web服务可能以完全出乎意料的方式用于攻击图像验证码。具体而言,在本文中,我们考虑了三种特定类型的Web服务:1)反向图像搜索(RIS),2)图像相似性搜索(ISS)和3)自动语言注释(ALA)。我们展示了这些基于图像的Web服务的功能如何与正则表达式,关键字本体和一些统计分析/推论结合使用,可以构成危险的攻击,轻松绕过典型图像验证码所面临的难题中的硬AI问题。我们还将讨论有效的防御措施,这些措施可用于使CAPTCHA对这些Web服务提供的攻击媒介具有更强的抵抗力。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号