首页> 外文期刊>Computers & Security >Pitfalls in CAPTCHA design and implementation: The Math CAPTCHA, a case study
【24h】

Pitfalls in CAPTCHA design and implementation: The Math CAPTCHA, a case study

机译:验证码设计和实施中的陷阱:数学验证码,案例研究

获取原文
获取原文并翻译 | 示例
       

摘要

We present a black-box attack against an already deployed CAPTCHA that aims to protect a free service delivered using the Internet. This CAPTCHA, referred to as "Math CAPTCHA" or "QRBGS CAPTCHA", requests the user to solve a mathematical problem in order to prove human. We study significant problems both in its design and its implementation, and how those flaws can be used to completely solve this CAPTCHA using a low-cost attack. This attack requires no development in Artificial Intelligence or automatic character recognition, the intended path, thus becoming a side-channel attack, based on the previously mentioned CAPTCHAs flaws. We relate these flaws to common flaws found in other CAPTCHA proposals. We conclude with some tips for enhancing this CAPTCHA that can be considered as general guidelines.
机译:我们针对已经部署的CAPTCHA提出了黑盒攻击,旨在保护使用Internet交付的免费服务。该验证码,称为“数学验证码”或“ QRBGS验证码”,要求用户解决数学问题以证明人类。我们研究了其设计和实施中的重大问题,以及如何使用这些缺陷通过低成本攻击完全解决此验证码问题。基于前面提到的CAPTCHA缺陷,此攻击不需要开发人工智能或自动字符识别(即预期的路径),因此成为了旁道攻击。我们将这些缺陷与其他CAPTCHA建议中发现的常见缺陷联系起来。我们以增强该验证码的一些技巧作为总结,可以将其视为一般准则。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号