首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Security Analysis and Related Usability of Motion-Based CAPTCHAs: Decoding Codewords in Motion
【24h】

Security Analysis and Related Usability of Motion-Based CAPTCHAs: Decoding Codewords in Motion

机译:基于运动的验证码的安全性分析和相关可用性:解码运动中的代码字

获取原文
获取原文并翻译 | 示例

摘要

We explore the robustness and usability of moving-image object recognition (video) captchas, designing and implementing automated attacks based on computer vision techniques. Our approach is suitable for broad classes of moving-image captchas involving rigid objects. We first present an attack that defeats instances of such a captcha (NuCaptcha) representing the state-of-the-art, involving dynamic text strings called codewords. We then consider design modifications to mitigate the attacks (e.g., overlapping characters more closely, randomly changing the font of individual characters, or even randomly varying the number of characters in the codeword). We implement the modified captchas and test if designs modified for greater robustness maintain usability. Our lab-based studies show that the modified captchas fail to offer viable usability, even when the captcha strength is reduced below acceptable targets. Worse yet, our GPU-based implementation shows that our automated approach can decode these captchas faster than humans can, and we can do so at a relatively low cost of roughly 50 cents per 1,000 captchas solved based on Amazon EC2 rates circa 2012. To further demonstrate the challenges in designing usable captchas, we also implement and test another variant of moving text strings using the known emerging images concept. This variant is resilient to our attacks and also offers similar usability to commercially available approaches. We explain why fundamental elements of the emerging images idea resist our current attack where others fail.
机译:我们探索了运动图像对象识别(视频)验证码的鲁棒性和可用性,设计并实现了基于计算机视觉技术的自动攻击。我们的方法适用于涉及刚性物体的各种活动图像验证码。我们首先提出一种攻击,该攻击可以消除代表最新技术的此类验证码(NuCaptcha)实例,其中涉及称为代码字的动态文本字符串。然后,我们考虑进行设计修改以减轻攻击(例如,更紧密地重叠字符,随机更改单个字符的字体,甚至随机更改代码字中的字符数)。我们实施修改后的验证码,并测试为提高鲁棒性而修改的设计是否保持可用性。我们基于实验室的研究表明,即使验证码强度降低到可接受的目标以下,修改的验证码也无法提供可行的可用性。更糟糕的是,基于GPU的实现表明,我们的自动化方法可以比人类更快地解码验证码,而且我们可以以相对较低的成本(基于大约2012年的Amazon EC2汇率解决每千个验证码50美分)来进行解码。演示了设计可用的验证码所面临的挑战,我们还使用已知的新兴图像概念实施并测试了移动文本字符串的另一种变体。此变体可以抵抗我们的攻击,并且还提供与市售方法相似的可用性。我们将解释新兴图像概念的基本元素为何会在其他失败的情况下抵抗我们目前的攻击。<​​/ p>

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号