首页> 外文OA文献 >The robustness of hollow CAPTCHAs
【2h】

The robustness of hollow CAPTCHAs

机译:空心验证码的鲁棒性

摘要

CAPTCHA is now a standard security technology for differentiating between computers and humans, and the most widely deployed schemes are text-based. While many text schemes have been broken, hollow CAPTCHAs have emerged as one of the latest designs, and they have been deployed by major companies such as Yahoo!, Tencent, Sina, China Mobile and Baidu. A main feature of such schemes is to use contour lines to form connected hollow characters with the aim of improving security and usability simultaneously, as it is hard for standard techniques to segment and recognize such connected characters, which are however easy to human eyes. In this paper, we provide the first analysis of hollow CAPTCHAs' robustness. We show that with a simple but novel attack, we can successfully break a whole family of hollow CAPTCHAs, including those deployed by all the major companies. While our attack casts serious doubt on the viability of current designs, we offer lessons and guidelines for designing better hollow CAPTCHAs. © 2013 ACM.
机译:现在,CAPTCHA是用于区分计算机和人的标准安全技术,并且部署最广泛的方案是基于文本的。尽管许多文本方案已被打破,但空心的验证码已成为最新的设计之一,并已由Yahoo !、腾讯,新浪,中国移动和百度等主要公司部署。这种方案的主要特征是使用轮廓线来形成连接的空心字符,以同时提高安全性和可用性,因为标准技术难以分割和识别这种连接的字符,但是人眼却很容易。在本文中,我们对空心验证码的鲁棒性进行了首次分析。我们证明,通过简单但新颖的攻击,我们就可以成功打破整个空洞的CAPTCHA家族,包括所有大型公司部署的那些。虽然我们的攻击对当前设计的可行性提出了严重怀疑,但我们提供了设计更好的空心CAPTCHA的课程和准则。 ©2013 ACM。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号