...
首页> 外文期刊>IEICE Transactions on Fundamentals of Electronics, Communications and Computer Sciences >Mitigating Dictionary Attacks with Text-Graphics Character CAPTCHAs
【24h】

Mitigating Dictionary Attacks with Text-Graphics Character CAPTCHAs

机译:使用文本图形字符验证码缓解字典攻击

获取原文
获取原文并翻译 | 示例
           

摘要

We propose a new construct, the Text-Graphics Character (TGC) CAPTCHA, for preventing dictionary attacks against password authentication systems allowing remote access via dumb terminals. Password authentication is commonly used for computer access control. But password authentication systems are prone to dictionary attacks, in which attackers repeatedly attempt to gain access using the entries in a list of frequently-used passwords. CAPTCHAs (Completely Automated Public Turing tests to tell Computers and Humans Apart) are currently being used to prevent automated "bots" from registering for email accounts. They have also been suggested as a means for preventing dictionary attacks. However, current CAPTCHAs are unsuitable for text-based remote access. TGC CAPTCHAs fill this gap. In this paper, we define two TGC CAPTCHAs and incorporate one of them in a prototype based on the SSH (Secure Shell) protocol suite. We also prove that, if a TGC CAPTCHA is easy for humans and hard for machines, then the resulting CAPTCHA is secure. We provide empirical evidence that our TGC CAPTCHAs are indeed easy for humans and hard for machines through a series of experiments. We believe that a system exploiting a TGC CAPTCHA will not only help improve the security of servers allowing remote terminal access, but also encourage a healthy spirit of competition in the fields of pattern recognition, computer graphics, and psychology.
机译:我们提出了一种新的结构,即文本图形字符(TGC)CAPTCHA,用于防止针对允许通过哑终端进行远程访问的密码验证系统的字典攻击。密码身份验证通常用于计算机访问控制。但是密码认证系统容易受到字典攻击,在这种攻击中,攻击者反复尝试使用常用密码列表中的条目来获得访问权限。目前正使用CAPTCHA(完全自动化的公共Turing测试来告诉计算机和人类分开),以防止自动化的“机器人”注册电子邮件帐户。还建议将它们作为防止字典攻击的手段。但是,当前的CAPTCHA不适合基于文本的远程访问。 TGC验证码填补了这一空白。在本文中,我们定义了两个TGC CAPTCHA,并将其中一个纳入基于SSH(安全外壳)协议套件的原型中。我们还证明,如果TGC CAPTCHA对人类来说很容易,对机器而言则很困难,那么生成的CAPTCHA是安全的。我们提供的经验证据表明,通过一系列实验,我们的TGC CAPTCHA实际上对人类来说很容易,对机器来说却很困难。我们相信,使用TGC CAPTCHA的系统不仅有助于提高允许远程终端访问的服务器的安全性,而且可以在模式识别,计算机图形学和心理学领域鼓励健康的竞争精神。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号