首页> 外文期刊>Computing and Information Systems >Mitigating CAPTCHA Relay Attacks Using Multiple Challenge-Response Mechanism
【24h】

Mitigating CAPTCHA Relay Attacks Using Multiple Challenge-Response Mechanism

机译:使用多重质询-响应机制缓解CAPTCHA中继攻击

获取原文
获取原文并翻译 | 示例
           

摘要

In an early work (Longe et al, 2009), we showed that existing CAPTCHA systems are majorly single challenge-response system, thus making it easy for bots and zombies to answer the test and consequently defeat the authentication mechanism. We introduced Double CAPTCHA Challenge-Response Systems (D-CRs) as a means of overcoming the inadequacies of the single challenge-response system and a viable tool in curbing internet masquerading. Since attackers such as spammers now use unsuspecting humans rather than automated script to solve CAPTCHAS, what is needed to break a CAPTCHA is to find human users willing to do the bidding of the hackers and fraudsters for a price. The consequence is the emergence of a new and challenging scenario commonly referred to as CAPTCHA relay attack. This paper describes how CAPTCHA relay attacks works in principle and how a Multiple challenge-response (M-CRs) system can be employed to mitigate CAPTCHA relay attacks using Multiple Challenge-Response mechanisms (M-CRs).
机译:在早期工作中(Longe等,2009),我们证明了现有的验证码系统主要是单一的挑战响应系统,从而使僵尸和僵尸很容易回答测试并因此破坏了身份验证机制。我们推出了Double CAPTCHA质询-响应系统(D-CR),以克服单一质询-响应系统的不足和控制互联网伪装的可行工具。由于诸如垃圾邮件发送者之类的攻击者现在使用的是毫无戒心的人而不是自动脚本来解决CAPTCHAS,因此打破CAPTCHA所需要的是找到愿意以高价竞标黑客和欺诈者的人类用户。结果是出现了一种新的具有挑战性的场景,通常称为CAPTCHA中继攻击。本文介绍了原理上的验证码中继攻击是如何工作的,以及如何使用多重质询-响应机制(M-CR)来利用多重质询-响应(M-CR)系统减轻CAPTCHA中继攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号