首页> 外文会议>Annual ACM symposium on applied computing;ACM symposium on applied computing;SAC 2010 >CAPTCHA Smuggling:Hijacking Web Browsing Sessions to Create CAPTCHA Farms
【24h】

CAPTCHA Smuggling:Hijacking Web Browsing Sessions to Create CAPTCHA Farms

机译:验证码走私:劫持Web浏览会话以创建验证码场

获取原文
获取外文期刊封面目录资料

摘要

CAPTCHAs protect online resources and services from automated access. From an attacker's point of view, they are typically perceived as an annoyance that prevents the mass creation of accounts or the automated posting of messages. Hence, miscreants strive to effectively bypass these protection mechanisms, using techniques such as optical character recognition or machine learning. However, as CAPTCHA systems evolve, they become more resilient against automated analysis approaches.In this paper, we introduce and evaluate an attack that we denote as CAPTCHA smuggling. To perform CAPTCHA smuggling, the attacker slips CAPTCHA challenges into the web browsing sessions of unsuspecting victims, misusing their ability to solve these challenges. A key point of our attack is that the CAPTCHAs are surreptitiously injected into interactions with benign web applications (such as web mail or social networking sites). As a result, they are perceived as a normal part of the application and raise no suspicion. Our evaluation, based on realistic user experiments, shows that CAPTCHA smuggling attacks are feasible in practice.
机译:验证码可保护在线资源和服务免受自动访问。从攻击者的角度来看,它们通常被看作是烦人的事,阻止了帐户的大量创建或邮件的自动发布。因此,不法分子使用诸如光学字符识别或机器学习之类的技术来努力绕开这些保护机制。但是,随着CAPTCHA系统的发展,它们对自动分析方法的适应能力也越来越强。 在本文中,我们介绍并评估了一种被称为CAPTCHA走私的攻击。为了执行CAPTCHA走私,攻击者将CAPTCHA挑战滑入了毫无戒心的受害者的Web浏览会话中,从而滥用了他们解决这些挑战的能力。我们攻击的重点是,将验证码秘密地注入与良性Web应用程序(例如Web邮件或社交网站)的交互中。结果,它们被视为应用程序的正常部分,并且毫无疑问。基于实际用户实验的评估表明,CAPTCHA走私攻击在实践中是可行的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号