Research on the Security of Visual Reasoning CAPTCHA

被引:0
|
作者
Gao, Yipeng [1 ]
Gao, Haichang [1 ]
Luo, Sainan [1 ]
Zi, Yang [1 ]
Zhang, Shudong [1 ]
Mao, Wenjie [1 ]
Wang, Ping [1 ]
Shen, Yulong [1 ]
Yan, Jeff [2 ]
机构
[1] Xidian Univ, Sch Comp Sci & Technol, Xian, Peoples R China
[2] Linkoping Univ, Dept Comp & Informat Sci, Linkoping, Sweden
来源
PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM | 2021年
关键词
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
CAPTCHA is an effective mechanism for protecting computers from malicious bots. With the development of deep learning techniques, current mainstream text-based CAPTCHAs have been proven to be insecure. Therefore, a major effort has been directed toward developing image-based CAPTCHAs, and image-based visual reasoning is emerging as a new direction of such development. Recently, Tencent deployed the Visual Turing Test (VTT) CAPTCHA. This appears to have been the first application of a visual reasoning scheme. Subsequently, other CAPTCHA service providers (Geetest, NetEase, Dingxiang, etc.) have proposed their own visual reasoning schemes to defend against bots. It is, therefore, natural to ask a fundamental question: are visual reasoning CAPTCHAs as secure as their designers expect? This paper presents the first attempt to solve visual reasoning CAPTCHAs. We implemented a holistic attack and a modular attack, which achieved overall success rates of 67.3% and 88.0% on VTT CAPTCHA, respectively. The results show that visual reasoning CAPTCHAs are not as secure as anticipated; this latest effort to use novel, hard AI problems for CAPTCHAs has not yet succeeded. Based on the lessons we learned from our attacks, we also offer some guidelines for designing visual CAPTCHAs with better security.
引用
收藏
页码:3291 / 3308
页数:18
相关论文
共 50 条
  • [21] Generating Arabic Handwritten CAPTCHA for Cyber Security
    Alsuhibany, Suliman A.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2018, 18 (03): : 41 - 47
  • [22] Visual Question Answering Research on Joint Knowledge and Visual Information Reasoning
    Su, Zhenqiang
    Gou, Gang
    Computer Engineering and Applications, 2024, 60 (05) : 95 - 102
  • [23] CAPTCHA: Impact of Website Security on User Experience
    Tanthavech, Nitirat
    Nimkoompai, Apichaya
    PROCEEDINGS OF 2019 4TH INTERNATIONAL CONFERENCE ON INTELLIGENT INFORMATION TECHNOLOGY (ICIIT 2019), 2019, : 37 - 41
  • [24] Visual CAPTCHA for Data Understanding and Cognitive Management
    Krzyworzeka, Natalia
    Ogiela, Lidia
    ADVANCES ON BROAD-BAND WIRELESS COMPUTING, COMMUNICATION AND APPLICATIONS, BWCCA-2017, 2018, 12 : 249 - 255
  • [25] Visual Cognitive CAPTCHA Based on Expert Knowledge
    Ogiela, Lidia
    Ogiela, Marek R.
    PROCEEDINGS OF 2019 11TH INTERNATIONAL CONFERENCE ON COMPUTER AND AUTOMATION ENGINEERING (ICCAE 2019), 2019, : 17 - 20
  • [26] A review of emerging research directions in Abstract Visual Reasoning
    Malkinski, Mikolaj
    Mandziuk, Jacek
    INFORMATION FUSION, 2023, 91 : 713 - 736
  • [27] Enhancing the Security of On-line Transactions with CAPTCHA Keyboard
    Wu, Yongdong
    Zhao, Zhigang
    INFORMATION SECURITY AND PRIVACY RESEARCH, 2012, 376 : 531 - 536
  • [28] A Multibiometrics-based CAPTCHA for Improved Online Security
    Powell, Brian M.
    Kumar, Abhishek
    Thapar, Jatin
    Goswami, Gaurav
    Vatsa, Mayank
    Singh, Richa
    Noore, Afzel
    2016 IEEE 8TH INTERNATIONAL CONFERENCE ON BIOMETRICS THEORY, APPLICATIONS AND SYSTEMS (BTAS), 2016,
  • [29] ADAMAS: Interweaving unicode and color to enhance CAPTCHA security
    Roshanbin, Narges
    Miller, James
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2016, 55 : 289 - 310
  • [30] Research and implementation of CAPTCHA based on Ajax
    School of Science Anhui University of Science and Technology, 232001 Huainan, China
    Chen, X., 1600, Springer Verlag (212):