DocumentCode
2904401
Title
GeoCAPTCHA — A novel personalized CAPTCHA using geographic concept to defend against 3rd Party Human Attack
Author
Te-En Wei ; Jeng, Albert B. ; Hahn-Ming Lee
Author_Institution
Dept. of Comput. Sci. & Inf. Eng., Nat. Taiwan Univ. of Sci. & Technol., Taipei, Taiwan
fYear
2012
fDate
1-3 Dec. 2012
Firstpage
392
Lastpage
399
Abstract
A CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) is a scheme that can be used to distinguish human and robot such as malicious program. It has become the most widely used standard security technology to prevent automated computer program attacks, DoS attacks and Botnet. Thus, both Google and Microsoft use the text-based CAPTCHA for authenticated process. However, all text-based CAPTCHA has been broken due to the fact that it can´t prevent Optical Character Recognition (OCR) attack which can automatically identify the CAPTCHA´s words. Consequently, new kinds of CAPTCHAs have been proposed to solve this security hole. For example, image-based and audio-based CAPTCHA are new emerging schemes used to replace text-based CAPTCHA. However, a state-of-the-art attack called Human Attack could still defeat these CAPTCHA schemes. Human Attack means malicious industries hire the third party´s humans to collude with the attackers in order to pass the CAPTCHA tests. In this paper, we propose a novel CAPTCHA scheme (GeoCAPTCHA) which utilizes the personalized contents such as geographic information to prevent the 3rd Party Human Attack. Then, we conduct a security analysis of the usability and security of GeoCAPTCHA. Our simulation demonstrate that GeoCAPTCHA can enhance the performance and security of the Google and Microsoft´s CATPCHA system with rotated 3D street-view image.
Keywords
Web sites; image processing; security of data; 3rd Party human attack; Botnet; CAPTCHA test; CAPTCHA word identification; Completely Automated Public Turing test to tell Computers and Humans Apart; DoS attack; GeoCAPTCHA; Google; Microsoft; OCR attack; audio-based CAPTCHA; authenticated process; automated computer program attack; geographic concept; geographic information; image-based CAPTCHA; malicious program; novel personalized CAPTCHA; optical character recognition; personalized content; rotated 3D street-view image; security analysis; security hole; security technology; text-based CAPTCHA; Computers; Databases; Google; Hip; Humans; Optical character recognition software; Security; 3rd Party Human Attack; Geographic; Image-based CAPTCHA; Personalized CAPTCHA;
fLanguage
English
Publisher
ieee
Conference_Titel
Performance Computing and Communications Conference (IPCCC), 2012 IEEE 31st International
Conference_Location
Austin, TX
ISSN
1097-2641
Print_ISBN
978-1-4673-4881-2
Type
conf
DOI
10.1109/PCCC.2012.6407782
Filename
6407782
Link To Document