首页> 外文期刊>Journal of computer security >On the security and usability of dynamic cognitive game CAPTCHAs
【24h】

On the security and usability of dynamic cognitive game CAPTCHAs

机译:动态认知游戏验证码的安全性和可用性

获取原文
获取原文并翻译 | 示例

摘要

Existing CAPTCHA solutions are a major source of user frustration on the Internet today, frequently forcing companies to lose customers and business. Game CAPTCHAs are a promising approach which may make CAPTCHA solving a fun activity for the user. One category of such CAPTCHAs - called Dynamic Cognitive Game (DCG) CAPTCHA - challenges the user to perform a game-like cognitive (or recognition) task interacting with a series of dynamic images. Specifically, it takes the form of many objects floating around within the images, and the user's task is to match the objects corresponding to specific target(s), and drag/drop them to the target region(s). In this paper, we pursue a comprehensive analysis of DCG CAPTCHAs. We design and implement such CAPTCHAs, and dissect them across four broad but overlapping dimensions: (1) usability, (2) fully automated attacks, (3) human-solving relay attacks, and (4) hybrid attacks that combine the strengths of automated and relay attacks. Our study shows that DCG CAPTCHAs are highly usable, even on mobile devices and offer some resilience to relay attacks, but they are vulnerable to our proposed automated and hybrid attacks.
机译:现有的CAPTCHA解决方案是当今互联网上令用户感到沮丧的主要根源,经常迫使公司失去客户和业务。游戏验证码是一种有前途的方法,可以使验证码为用户解决有趣的活动。这种验证码的一个类别-称为动态认知游戏(DCG)验证码-挑战用户执行与一系列动态图像交互的类似游戏的认知(或识别)任务。具体来说,它采取许多对象在图像内浮动的形式,并且用户的任务是匹配与特定目标相对应的对象,并将它们拖放到目标区域。在本文中,我们将对DCG CAPTCHA进行全面分析。我们设计并实现了这样的验证码,并将其分解为四个广泛但重叠的维度:(1)可用性,(2)全自动攻击,(3)解决人类的中继攻击以及(4)结合了自动化优势的混合攻击和中继攻击。我们的研究表明,即使在移动设备上,DCG CAPTCHA也是高度可用的,并且具有中继攻击的弹性,但是它们容易受到我们提出的自动和混合攻击的攻击。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号