Improving Security Control of Text-Based CAPTCHA Challenges using Honeypot and Timestamping

M. T. Banday, Shafiya Afzal Sheikh
{"title":"Improving Security Control of Text-Based CAPTCHA Challenges using Honeypot and Timestamping","authors":"M. T. Banday, Shafiya Afzal Sheikh","doi":"10.1109/ICCMC48092.2020.ICCMC-000131","DOIUrl":null,"url":null,"abstract":"The resistance to attacks aimed to break CAPTCHA challenges and the effectiveness, efficiency and satisfaction of human users in solving them called usability are the two major concerns while designing CAPTCHA schemes. User-friendliness, universality, and accessibility are related dimensions of usability, which must also be addressed adequately. With recent advances in segmentation and optical character recognition techniques, complex distortions, degradations and transformations are added to text-based CAPTCHA challenges resulting in their reduced usability. The extent of these deformations can be decreased if some additional security mechanism is incorporated in such challenges. This paper proposes an additional security mechanism that can add an extra layer of protection to any text-based CAPTCHA challenge, making it more challenging for bots and scripts that might be used to attack websites and web applications. It proposes the use of hidden text-boxes for user entry of CAPTCHA string which serves as honeypots for bots and automated scripts. The honeypot technique is used to trick bots and automated scripts into filling up input fields which legitimate human users cannot fill in. The paper reports implementation of honeypot technique and results of tests carried out over three months during which form submissions were logged for analysis. The results demonstrated great effectiveness of honeypots technique to improve security control and usability of text-based CAPTCHA challenges.","PeriodicalId":130581,"journal":{"name":"2020 Fourth International Conference on Computing Methodologies and Communication (ICCMC)","volume":"48 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-03-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 Fourth International Conference on Computing Methodologies and Communication (ICCMC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCMC48092.2020.ICCMC-000131","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1

Abstract

The resistance to attacks aimed to break CAPTCHA challenges and the effectiveness, efficiency and satisfaction of human users in solving them called usability are the two major concerns while designing CAPTCHA schemes. User-friendliness, universality, and accessibility are related dimensions of usability, which must also be addressed adequately. With recent advances in segmentation and optical character recognition techniques, complex distortions, degradations and transformations are added to text-based CAPTCHA challenges resulting in their reduced usability. The extent of these deformations can be decreased if some additional security mechanism is incorporated in such challenges. This paper proposes an additional security mechanism that can add an extra layer of protection to any text-based CAPTCHA challenge, making it more challenging for bots and scripts that might be used to attack websites and web applications. It proposes the use of hidden text-boxes for user entry of CAPTCHA string which serves as honeypots for bots and automated scripts. The honeypot technique is used to trick bots and automated scripts into filling up input fields which legitimate human users cannot fill in. The paper reports implementation of honeypot technique and results of tests carried out over three months during which form submissions were logged for analysis. The results demonstrated great effectiveness of honeypots technique to improve security control and usability of text-based CAPTCHA challenges.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
使用蜜罐和时间戳改进基于文本的CAPTCHA挑战的安全控制
在设计CAPTCHA方案时,对旨在打破CAPTCHA挑战的攻击的抵抗力以及人类用户在解决这些挑战时的有效性、效率和满意度(称为可用性)是两个主要关注的问题。用户友好性、通用性和可访问性是可用性的相关方面,也必须充分加以处理。随着分割和光学字符识别技术的最新进展,复杂的扭曲、退化和转换被添加到基于文本的CAPTCHA挑战中,导致其可用性降低。如果在这些挑战中加入一些额外的安全机制,则可以减少这些变形的程度。本文提出了一种额外的安全机制,可以为任何基于文本的CAPTCHA挑战添加额外的保护层,使可能用于攻击网站和web应用程序的机器人和脚本更具挑战性。它建议使用隐藏文本框为用户输入CAPTCHA字符串,作为机器人和自动脚本的蜜罐。蜜罐技术用于欺骗机器人和自动脚本,使其填写合法用户无法填写的输入字段。本文报告了蜜罐技术的实施情况和三个月来进行的测试结果,在此期间记录了提交的表格以供分析。结果证明了蜜罐技术在提高基于文本的验证码挑战的安全性控制和可用性方面的巨大有效性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Analysis of Time Domain Features of Dysarthria Speech Tourism Recommendation System based on Knowledge Graph Feature Learning IoT systems based on SOA services: Methodologies, Challenges and Future directions Wildfire forecast within the districts of Kerala using Fuzzy and ANFIS A Review Study on the Multiple and Useful Application of Fiber Optic Illumination System
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1