DocumentCode :
2904401
Title :
GeoCAPTCHA — A novel personalized CAPTCHA using geographic concept to defend against 3rd Party Human Attack
Author :
Te-En Wei ; Jeng, Albert B. ; Hahn-Ming Lee
Author_Institution :
Dept. of Comput. Sci. & Inf. Eng., Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
fYear :
2012
fDate :
1-3 Dec. 2012
Firstpage :
392
Lastpage :
399
Abstract :
A CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) is a scheme that can be used to distinguish human and robot such as malicious program. It has become the most widely used standard security technology to prevent automated computer program attacks, DoS attacks and Botnet. Thus, both Google and Microsoft use the text-based CAPTCHA for authenticated process. However, all text-based CAPTCHA has been broken due to the fact that it can´t prevent Optical Character Recognition (OCR) attack which can automatically identify the CAPTCHA´s words. Consequently, new kinds of CAPTCHAs have been proposed to solve this security hole. For example, image-based and audio-based CAPTCHA are new emerging schemes used to replace text-based CAPTCHA. However, a state-of-the-art attack called Human Attack could still defeat these CAPTCHA schemes. Human Attack means malicious industries hire the third party´s humans to collude with the attackers in order to pass the CAPTCHA tests. In this paper, we propose a novel CAPTCHA scheme (GeoCAPTCHA) which utilizes the personalized contents such as geographic information to prevent the 3rd Party Human Attack. Then, we conduct a security analysis of the usability and security of GeoCAPTCHA. Our simulation demonstrate that GeoCAPTCHA can enhance the performance and security of the Google and Microsoft´s CATPCHA system with rotated 3D street-view image.
Keywords :
Web sites; image processing; security of data; 3rd Party human attack; Botnet; CAPTCHA test; CAPTCHA word identification; Completely Automated Public Turing test to tell Computers and Humans Apart; DoS attack; GeoCAPTCHA; Google; Microsoft; OCR attack; audio-based CAPTCHA; authenticated process; automated computer program attack; geographic concept; geographic information; image-based CAPTCHA; malicious program; novel personalized CAPTCHA; optical character recognition; personalized content; rotated 3D street-view image; security analysis; security hole; security technology; text-based CAPTCHA; Computers; Databases; Google; Hip; Humans; Optical character recognition software; Security; 3rd Party Human Attack; Geographic; Image-based CAPTCHA; Personalized CAPTCHA;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Performance Computing and Communications Conference (IPCCC), 2012 IEEE 31st International
Conference_Location :
Austin, TX
ISSN :
1097-2641
Print_ISBN :
978-1-4673-4881-2
Type :
conf
DOI :
10.1109/PCCC.2012.6407782
Filename :
6407782
Link To Document :
بازگشت