Skip to main content

2018 | OriginalPaper | Buchkapitel

An Examination of CAPTCHA for Tolerance of Relay Attacks and Automated Attacks

verfasst von : Ryohei Tatsuda, Hisaaki Yamaba, Kentaro Aburada, Tetsuro Katayama, Mirang Park, Norio Shiratori, Naonobu Okazaki

Erschienen in: Advances in Internet, Data & Web Technologies

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

CAPTCHA is a type of challenge response test used to distinguish human users from malicious computer programs such as bots, and is used to protect email, blogs, and other web services from bot attacks. So far, research on enhance of CAPTCHA’s resistance to bot attacks has been proceeded to counter advanced automated attacks method. However, an attack technique known as a relay attack has been devised to circumvent CAPTCHA. In this attack, since human solves CAPTCHA, the existing measures assuming bots have no effect on this attack. We designed a new CAPTCHA scheme for relay attacks tolerance and automated attacks tolerance. In this paper, we tested the robustness of the proposed method against several types of automated attacks. We constructed an experimental environment in which a relay attack can be simulated, and designed a series of experiments to evaluate the performance of the proposed method. As a result, we found that the proposed CAPTCHA scheme offers some of level of resistance to automated attacks and relay attacks.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat von Ahn, L., Blum, M., Hopper, N.J., Langford, J.: CAPTCHA: telling humans and computers apart automatically. In: Advances in Cryptology, Eurocrypt 2003, Lecture Notes in Computer Science, vol. 2656, pp. 294–311 (2003) von Ahn, L., Blum, M., Hopper, N.J., Langford, J.: CAPTCHA: telling humans and computers apart automatically. In: Advances in Cryptology, Eurocrypt 2003, Lecture Notes in Computer Science, vol. 2656, pp. 294–311 (2003)
2.
Zurück zum Zitat Mohamed, M., Sachdeva, N., Georgescu, M., Gao, S., Zhang, C.: A three-way investigation of a game-CAPTCHA: automated attacks, relay attacks and usability. In: Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security, pp. 195–206. ACM (2014) Mohamed, M., Sachdeva, N., Georgescu, M., Gao, S., Zhang, C.: A three-way investigation of a game-CAPTCHA: automated attacks, relay attacks and usability. In: Proceedings of the 9th ACM Symposium on Information, Computer and Communications Security, pp. 195–206. ACM (2014)
3.
Zurück zum Zitat Mohamed, M., Gao, S., Saxena, N., Zhang, C.: Dynamic cognitive game CAPTCHA usability and detection of streaming-based farming. In: The Workshop on Usable Security (USEC), Co-located with NDSS (2014) Mohamed, M., Gao, S., Saxena, N., Zhang, C.: Dynamic cognitive game CAPTCHA usability and detection of streaming-based farming. In: The Workshop on Usable Security (USEC), Co-located with NDSS (2014)
4.
Zurück zum Zitat Khan, I.R., Farbiz, F.: A back projection scheme for accurate mean shift based tracking. In: 2010 17th IEEE International Conference on Image Processing (ICIP), pp. 33–36. IEEE (2010) Khan, I.R., Farbiz, F.: A back projection scheme for accurate mean shift based tracking. In: 2010 17th IEEE International Conference on Image Processing (ICIP), pp. 33–36. IEEE (2010)
6.
Zurück zum Zitat Yan, J., EI Ahmad, A.S.: Usability of CAPTCHAs or usability issues in CAPTCHA design. In: Proceedings of the 4th Symposium on Usable Privacy and Security, pp. 44–52. ACM (2008) Yan, J., EI Ahmad, A.S.: Usability of CAPTCHAs or usability issues in CAPTCHA design. In: Proceedings of the 4th Symposium on Usable Privacy and Security, pp. 44–52. ACM (2008)
7.
Zurück zum Zitat Motoyama, M., Levchenko, K., Kanich, C., McCoy, D., Coelker, G.M., Savage, S.: Re: CAPTCHAs-Understanding CAPTCHA-Solving Services in an Economic Context. In: USENIX Security Symposium, Washington, pp. 1–18 (2010) Motoyama, M., Levchenko, K., Kanich, C., McCoy, D., Coelker, G.M., Savage, S.: Re: CAPTCHAs-Understanding CAPTCHA-Solving Services in an Economic Context. In: USENIX Security Symposium, Washington, pp. 1–18 (2010)
8.
Zurück zum Zitat Bohan, M., Chaparro, A.: Age-related differences in performance using a mouse and trackball. Proc. Hum. Factors Ergon. Soc. Ann. Meet. 42(2), 152–155 (1998) Bohan, M., Chaparro, A.: Age-related differences in performance using a mouse and trackball. Proc. Hum. Factors Ergon. Soc. Ann. Meet. 42(2), 152–155 (1998)
9.
Zurück zum Zitat Zende, S., Tambile, V., Thakur, A., Schendge, M., Rathi, S.: Mouse pointer movement using Gaze tracking system. Int. J. Comput. Appl. 140(11), 1–4 (2016) Zende, S., Tambile, V., Thakur, A., Schendge, M., Rathi, S.: Mouse pointer movement using Gaze tracking system. Int. J. Comput. Appl. 140(11), 1–4 (2016)
Metadaten
Titel
An Examination of CAPTCHA for Tolerance of Relay Attacks and Automated Attacks
verfasst von
Ryohei Tatsuda
Hisaaki Yamaba
Kentaro Aburada
Tetsuro Katayama
Mirang Park
Norio Shiratori
Naonobu Okazaki
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-319-75928-9_80

Premium Partner