DocumentCode :
22606
Title :
Security Analysis and Related Usability of Motion-Based CAPTCHAs: Decoding Codewords in Motion
Author :
Yi Xu ; Reynaga, Gerardo ; Chiasson, Sonia ; Frahm, Jan-Michael ; Monrose, F. ; van Oorschot, Paul C.
Author_Institution :
Dept. of Comput. Sci., Univ. of North Carolina at Chapel Hill, Chapel Hill, NC, USA
Volume :
11
Issue :
5
fYear :
2014
fDate :
Sept.-Oct. 2014
Firstpage :
480
Lastpage :
493
Abstract :
We explore the robustness and usability of moving-image object recognition (video) CAPTCHAS, designing and implementing automated attacks based on computer vision techniques. Our approach is suitable for broad classes of moving-image CAPTCHAS involving rigid objects. We first present an attack that defeats instances of such a CAPTCHA (NuCaptcha) representing the state-of-the-art, involving dynamic text strings called codewords. We then consider design modifications to mitigate the attacks (e.g., overlapping characters more closely, randomly changing the font of individual characters, or even randomly varying the number of characters in the codeword). We implement the modified CAPTCHAS and test if designs modified for greater robustness maintain usability. Our lab-based studies show that the modified captchas fail to offer viable usability, even when the captcha strength is reduced below acceptable targets. Worse yet, our GPU-based implementation shows that our automated approach can decode these captchas faster than humans can, and we can do so at a relatively low cost of roughly 50 cents per 1,000 captchas solved based on Amazon EC2 rates circa 2012. To further demonstrate the challenges in designing usable captchas, we also implement and test another variant of moving text strings using the known emerging images concept. This variant is resilient to our attacks and also offers similar usability to commercially available approaches. We explain why fundamental elements of the emerging images idea resist our current attack where others fail.
Keywords :
Turing machines; computer vision; graphics processing units; image coding; image motion analysis; object recognition; security of data; text analysis; Amazon EC2 rates circa strings; GPU-based implementation; automated attack mitigation; computer vision; decoding codeword; design modification; dynamic text strings; motion-based CAPTCHA; moving image object recognition CAPTCHA; security analysis; usability analysis; CAPTCHAs; Feature extraction; Image color analysis; Robustness; Streaming media; Trajectory; Usability; CAPTCHAs; computer vision; security; usability;
fLanguage :
English
Journal_Title :
Dependable and Secure Computing, IEEE Transactions on
Publisher :
ieee
ISSN :
1545-5971
Type :
jour
DOI :
10.1109/TDSC.2013.52
Filename :
6682912
Link To Document :
بازگشت