arrow
Return

Using machine learning to identify common flaws in CAPTCHA design: FunCAPTCHA case analysis

delete2017-09-01
delete2
delete
OA
AI
C
Carlos Javier Hernández‐Castro *
M
María D. R‐Moreno
D
David F. Barrero
S
Stuart Gibson
DOI:10.1016/j.cose.2017.05.005delete
deleteOriginal
deleteShare
deleteSave
View PDF
Abstract

Abstract

En 中文
Human Interactive Proofs (HIPS (1) or CAPTCHAs (2)) have become a first-level security measure on the Internet to avoid automatic attacks or minimize their effects. All the most widespread, successful or interesting CAPTCHA designs put to scrutiny have been successfully broken. Many of these attacks have been side-channel attacks. New designs are proposed to tackle these security problems while improving the human interface. FunCAPTCHA is the first commercial implementation of a gender classification CAPTCHA, with reported improvements in conversion rates. This article finds weaknesses in the security of FunCAPTCHA and uses simple machine learning (ML) analysis to test them. It shows a side-channel attack that leverages these flaws and successfully solves FunCAPTCHA on 90% of occasions without using meaningful image analysis. This simple yet effective security analysis can be applied with minor modifications to other HIPs proposals, allowing to check whether they leak enough information that would in turn allow for simple side-channel attacks. (C) 2017 Elsevier Ltd. All rights reserved.
Keywords:
HIP
CAPTCHA
Machine learning
Gender classification
Side-channel attack
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

C
Computers and Security
IF:
5.4
Papers:
4.6K
Citations:
1.4W

Organization

C
Complutense University of Madrid
Scholars:
2.6W
Papers: 2.2W
Citations: 31
U
universidad de alcala
Scholars:
7.9K
Papers: 6.8K
Citations: 7
U
University of Kent
Scholars:
5.3K
Papers: 6.1K
Citations: 8.1K
researcher View more organizations