基本信息来源于合作网站,原文需代理用户跳转至来源网站获取       
摘要:
Image captchas have recently become very popular and are widely deployed across the Internet to defend against abusive programs. However, the ever-advancing capabilities of computer vision have gradually diminished the security of image captchas and made them vulnerable to attack. In this paper, we first classify the currently popular image captchas into three categories: selection-based captchas, slide-based captchas, and click-based captchas. Second, we propose simple yet powerful attack frameworks against each of these categories of image captchas. Third, we systematically evaluate our attack frameworks against 10 popular real-world image captchas,including captchas from tencent.com, google.com, and 12306.cn. Fourth, we compare our attacks against nine online image recognition services and against human labors from eight underground captcha-solving services. Our evaluation results show that(1) each of the popular image captchas that we study is vulnerable to our attacks;(2) our attacks yield the highest captcha-breaking success rate compared with state-of-the-art methods in almost all scenarios;and(3) our attacks achieve almost as high a success rate as human labor while being much faster.Based on our evaluation, we identify some design flaws in these popular schemes, along with some best practices and design principles for more secure captchas. We also examine the underground market for captcha-solving services, identifying 152 such services. We then seek to measure this underground market with data from these services. Our findings shed light on understanding the scale, impact, and commercial landscape of the underground market for captcha solving.
推荐文章
基于SOAP网关的Web Services安全模型研究
Web
Services
SOAP
安全
网关
覆盖约简算法在Captcha识别方面的应用
Captcha识别
覆盖约简
条件信息熵
基于SOAP协议的Web Service 安全基础规范(WS-Security)
Web Service
WS-Security
安全规范
安全信息交换
SOAP协议扩展
内容分析
关键词云
关键词热度
相关文献总数  
(/次)
(/年)
文献信息
篇名 Towards Understanding the Security of Modern Image Captchas and Underground Captcha-Solving Services
来源期刊 大数据挖掘与分析(英文) 学科 工学
关键词 IMAGE captchas CAPTCHA SECURITY captcha-solving service UNDERGROUND market
年,卷(期) 2019,(2) 所属期刊栏目
研究方向 页码范围 118-144
页数 27页 分类号 TP391.41
字数 语种
DOI
五维指标
传播情况
(/次)
(/年)
引文网络
引文网络
二级参考文献  (0)
共引文献  (0)
参考文献  (0)
节点文献
引证文献  (0)
同被引文献  (0)
二级引证文献  (0)
2019(0)
  • 参考文献(0)
  • 二级参考文献(0)
  • 引证文献(0)
  • 二级引证文献(0)
研究主题发展历程
节点文献
IMAGE
captchas
CAPTCHA
SECURITY
captcha-solving
service
UNDERGROUND
market
研究起点
研究来源
研究分支
研究去脉
引文网络交叉学科
相关学者/机构
期刊影响力
大数据挖掘与分析(英文)
季刊
2096-0654
10-1514/G2
出版文献量(篇)
91
总下载数(次)
3
总被引数(次)
0
论文1v1指导