首页> 外文期刊>Computers & Security >All about uncertainties and traps: Statistical oracle-based attacks on a new CAPTCHA protection against oracle attacks
【24h】

All about uncertainties and traps: Statistical oracle-based attacks on a new CAPTCHA protection against oracle attacks

机译:所有关于不确定性和陷阱的信息:基于统计的基于oracle的攻击,针对新的CAPTCHA防御oracle攻击

获取原文
获取原文并翻译 | 示例
       

摘要

CAPTCHAs are security mechanisms that try to prevent automated abuse of computer services. Many CAPTCHAs have been proposed but most have known security flaws against advanced attacks. In order to avoid a kind of oracle attacks in which the attacker learns about ground truth labels via active interactions with the CAPTCHA service as an oracle, Kwon and Cha proposed a new CAPTCHA scheme that employ uncertainties and trap images to generate adaptive CAPTCHA challenges, which we call "Uncertainty and Trap Strengthened CAPTCHA" (UTS-CAPTCHA) in this paper. Adaptive CAPTCHA challenges are used widely (either explicitly or implicitly) but the role of such adaptive mechanisms in the security of CAPTCHAs has received little attention from researchers. In this paper we present a statistical fundamental design flaw of UTS-CAPTCHA. This flaw leaks information regarding ground truth labels of images used. Exploiting this flaw, an attacker can use the UTS-CAPTCHA service as an oracle, and perform several different statistical learning-based attacks against UTS-CAPTCHA, increasing any reasonable initial success rate up to 100% according to our theoretical estimation and experimental simulations. Based on our proposed attacks, we discuss how the fundamental idea behind our attacks may be generalized to attack other CAPTCHA schemes and propose a new principle and a number of concrete guidelines for designing new CAPTCHA schemes in the future.
机译:验证码是安全机制,旨在防止自动滥用计算机服务。已经提出了许多验证码,但是大多数都具有针对高级攻击的安全缺陷。为了避免一种Oracle攻击,攻击者通过与CAPTCHA服务作为Oracle的主动交互来了解地面真相标签,Kwon和Cha提出了一种新的CAPTCHA方案,该方案利用不确定性和陷阱图像来生成自适应CAPTCHA挑战,我们在本文中将其称为“不确定性和陷阱强化验证码”(UTS-CAPTCHA)。自适应CAPTCHA挑战被广泛使用(显式或隐式),但是这种自适应机制在CAPTCHA的安全性中的作用很少受到研究人员的关注。在本文中,我们介绍了UTS-CAPTCHA的统计基本设计缺陷。该缺陷泄漏了有关所使用图像的地面真相标签的信息。利用此漏洞,攻击者可以将UTS-CAPTCHA服务用作Oracle,并对UTS-CAPTCHA进行几种不同的基于统计学习的攻击,根据我们的理论估计和实验模拟,任何合理的初始成功率都可以提高到100%。基于我们提出的攻击,我们讨论如何将攻击背后的基本思想推广到攻击其他CAPTCHA方案的过程中,并提出新的原理和一些具体的准则,以供将来设计新的CAPTCHA方案之用。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号