返回
Using machine learning to identify common flaws in CAPTCHA design: FunCAPTCHA case analysis
DOI:10.1016/j.cose.2017.05.005.png)
摘要
En 中文
Human Interactive Proofs (HIPS (1) or CAPTCHAs (2)) have become a first-level security measure on the Internet to avoid automatic attacks or minimize their effects. All the most widespread, successful or interesting CAPTCHA designs put to scrutiny have been successfully broken. Many of these attacks have been side-channel attacks. New designs are proposed to tackle these security problems while improving the human interface. FunCAPTCHA is the first commercial implementation of a gender classification CAPTCHA, with reported improvements in conversion rates. This article finds weaknesses in the security of FunCAPTCHA and uses simple machine learning (ML) analysis to test them. It shows a side-channel attack that leverages these flaws and successfully solves FunCAPTCHA on 90% of occasions without using meaningful image analysis. This simple yet effective security analysis can be applied with minor modifications to other HIPs proposals, allowing to check whether they leak enough information that would in turn allow for simple side-channel attacks. (C) 2017 Elsevier Ltd. All rights reserved.
Keyword:
HIP
CAPTCHA
Machine learning
Gender classification
Side-channel attack
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
Electrical Conductivity of Reproductive Tissue for Detection of Estrus in Dairy Cows用于检测奶牛发情的繁殖组织电导率
A new image-based CAPTCHA using the orientation of the polygonally cropped sub-images
VISUAL COMPUTER
IF2.9
Gradient-based learning applied to document recognition基于梯度的学习在文档识别中的应用
PROCEEDINGS OF THE IEEE
IF25.9

