• DocumentCode
    541965
  • Title

    Side-channel attack on the HumanAuth CAPTCHA

  • Author

    Hernandez-Castro, Carlos Javier ; Ribagorda, Arturo ; Saez, Yago

  • Author_Institution
    Security Group, Department of Computer Science, Carlos III University, 28911 Leganes, Madrid, Spain
  • fYear
    2010
  • fDate
    26-28 July 2010
  • Firstpage
    1
  • Lastpage
    7
  • Abstract
    We propose a new scheme of attack on the HumanAuth CAPTCHA which represents a significant shortcut to the intended attacking path, as it is not based in any advance in the state of the art on the field of image recognition. After analyzing the HumanAuth image database with a new approach based on statistical analysis and machine learning, we conclude that it cannot fulfill the security objectives intended by its authors. Then, we analyze which of the studied parameters for the image files seem to disclose the most valuable information for helping in correct classification, arriving at a surprising discovery. We also analyze if the image watermarking algorithm presented by the HumanAuth authors is able to counter the effect of this new attack. Our attack represents a completely new approach to breaking image labeling CAPTCHAs, and can be applied to many of the currently proposed schemes. Lastly, we investigate some measures that could be used to increase the security of image labeling CAPTCHAs as HumanAuth, but conclude no easy solutions are at hand.
  • Keywords
    Accuracy; Computers; Correlation; Databases; Humans; Watermarking; Automatic classification; CAPTCHA; HumanAuth; Image labeling; Watermarking;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Cryptography (SECRYPT), Proceedings of the 2010 International Conference on
  • Conference_Location
    Athens
  • Type

    conf

  • Filename
    5741692