交互式视频验证码,更好地抵抗自动攻击

Shotaro Usuzaki, K. Aburada, H. Yamaba, T. Katayama, M. Mukunoki, Mirang Park, N. Okazaki
{"title":"交互式视频验证码,更好地抵抗自动攻击","authors":"Shotaro Usuzaki, K. Aburada, H. Yamaba, T. Katayama, M. Mukunoki, Mirang Park, N. Okazaki","doi":"10.23919/ICMU.2018.8653624","DOIUrl":null,"url":null,"abstract":"A “Completely Automated Public Turing Test to Tell Computers and Humans Apart” (CAPTCHA) widely used online services so that prevents bots from automatic getting a large of accounts. Interactive video type CAPTCHAs that attempt to detect this attack by using delay time due to communication relays have been proposed. However, these approaches remain insufficiently resistant to bots. We propose a CAPTCHA that combines resistant to automated and relay attacks. In our CAPTCHA, the users recognize a moving object (target object) from among a number of randomly appearing decoy objects and tracks the target with mouse cursor. The users pass the test when they were able to track the target for a certain time. Since the target object moves quickly, the delay makes it difficult for a remote solver to break the CAPTCHA during a relay attack. It is also difficult for a bot to track the target using image processing because it has same looks of the decoys. We evaluated our CAPTCHA’s resistance to relay and automated attacks. Our results show that, if our CAPTHCA’s parameters are set suitable value, a relay attack cannot be established economically and false acceptance rate with bot could be reduced to 0.01% without affecting human success rate.","PeriodicalId":398108,"journal":{"name":"2018 Eleventh International Conference on Mobile Computing and Ubiquitous Network (ICMU)","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":"{\"title\":\"Interactive Video CAPTCHA for Better Resistance to Automated Attack\",\"authors\":\"Shotaro Usuzaki, K. Aburada, H. Yamaba, T. Katayama, M. Mukunoki, Mirang Park, N. Okazaki\",\"doi\":\"10.23919/ICMU.2018.8653624\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"A “Completely Automated Public Turing Test to Tell Computers and Humans Apart” (CAPTCHA) widely used online services so that prevents bots from automatic getting a large of accounts. Interactive video type CAPTCHAs that attempt to detect this attack by using delay time due to communication relays have been proposed. However, these approaches remain insufficiently resistant to bots. We propose a CAPTCHA that combines resistant to automated and relay attacks. In our CAPTCHA, the users recognize a moving object (target object) from among a number of randomly appearing decoy objects and tracks the target with mouse cursor. The users pass the test when they were able to track the target for a certain time. Since the target object moves quickly, the delay makes it difficult for a remote solver to break the CAPTCHA during a relay attack. It is also difficult for a bot to track the target using image processing because it has same looks of the decoys. We evaluated our CAPTCHA’s resistance to relay and automated attacks. Our results show that, if our CAPTHCA’s parameters are set suitable value, a relay attack cannot be established economically and false acceptance rate with bot could be reduced to 0.01% without affecting human success rate.\",\"PeriodicalId\":398108,\"journal\":{\"name\":\"2018 Eleventh International Conference on Mobile Computing and Ubiquitous Network (ICMU)\",\"volume\":\"31 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-10-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"3\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2018 Eleventh International Conference on Mobile Computing and Ubiquitous Network (ICMU)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.23919/ICMU.2018.8653624\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 Eleventh International Conference on Mobile Computing and Ubiquitous Network (ICMU)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.23919/ICMU.2018.8653624","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

摘要

一个“完全自动化的公共图灵测试来区分计算机和人类”(CAPTCHA)广泛应用于在线服务,以防止机器人自动获得大量账户。交互式视频类型的captcha试图通过使用由于通信中继造成的延迟时间来检测这种攻击。然而,这些方法仍然不足以抵抗机器人。我们提出了一种结合了自动攻击和中继攻击的CAPTCHA。在我们的CAPTCHA中,用户从许多随机出现的诱饵对象中识别移动对象(目标对象),并使用鼠标光标跟踪目标。当用户能够在一段时间内跟踪目标时,他们就通过了测试。由于目标对象移动迅速,延迟使得远程求解器在中继攻击期间难以破解CAPTCHA。机器人也很难使用图像处理来跟踪目标,因为它与诱饵有相同的外观。我们评估了验证码对中继和自动攻击的抵抗力。我们的研究结果表明,如果我们的CAPTHCA参数设置合适的值,可以经济地建立中继攻击,并且在不影响人工成功率的情况下,机器人的错误接受率可以降低到0.01%。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Interactive Video CAPTCHA for Better Resistance to Automated Attack
A “Completely Automated Public Turing Test to Tell Computers and Humans Apart” (CAPTCHA) widely used online services so that prevents bots from automatic getting a large of accounts. Interactive video type CAPTCHAs that attempt to detect this attack by using delay time due to communication relays have been proposed. However, these approaches remain insufficiently resistant to bots. We propose a CAPTCHA that combines resistant to automated and relay attacks. In our CAPTCHA, the users recognize a moving object (target object) from among a number of randomly appearing decoy objects and tracks the target with mouse cursor. The users pass the test when they were able to track the target for a certain time. Since the target object moves quickly, the delay makes it difficult for a remote solver to break the CAPTCHA during a relay attack. It is also difficult for a bot to track the target using image processing because it has same looks of the decoys. We evaluated our CAPTCHA’s resistance to relay and automated attacks. Our results show that, if our CAPTHCA’s parameters are set suitable value, a relay attack cannot be established economically and false acceptance rate with bot could be reduced to 0.01% without affecting human success rate.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Modelling and Analysing Overlay Networks by Ambients with Wormholes VR Classroom: Enhancing Learning Experience with Virtual Class Rooms [Copyright notice] ICMU 2018 Committees Deep Reinforcement Learning-Based Method of Mobile Data Offloading
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1