Towards Evaluating the Security of Real-World Deployed Image CAPTCHAs

Towards Evaluating the Security of Real-World Deployed Image CAPTCHAs
复制标题

DOI:
10.1145/3270101.3270104
复制
发表时间:
2018-01
期刊:
Proceedings of the 11th ACM Workshop on Artificial Intelligence and Security
影响因子:
--
通讯作者:
Binbin Zhao;Haiqin Weng;S. Ji;Jianhai Chen;Ting Wang;Qinming He;Reheem Beyah
Binbin Zhao;Haiqin Weng;S. Ji;Jianhai Chen;Ting Wang;Qinming He;Reheem Beyah
中科院分区:
其他
文献类型:
--
作者:
Binbin Zhao;Haiqin Weng;S. Ji;Jianhai Chen;Ting Wang;Qinming He;Reheem Beyah

文献摘要

被引文献

相似文献

如今,图像验证码正在整个互联网上被广泛使用,以防御滥用程序。然而,计算机视觉技术不断进步的能力正在逐渐降低图像验证码的安全性;然而,到目前为止,人们对部署在现实世界中的图像验证码的脆弱性知之甚少。本文首次对野外图像验证码的安全性进行了系统的研究。我们将当前流行的图像验证码分为三类:基于选择的验证码、基于幻灯片的验证码和基于点击的验证码。我们提出了三种有效的通用攻击,每种攻击都针对这些类别中的一种。我们评估了我们针对10个真实世界流行图片验证码的攻击,包括来自tencent.com、google.com和12306.cn的攻击。此外,我们将我们的攻击与9个在线图像识别服务和8个地下验证码解决服务的人工进行了比较。我们的研究表明:(1)所有流行的图像验证码都容易受到我们的攻击;(2)我们的攻击在几乎所有场景中都显著优于最先进的图像验证码;(3)我们的攻击取得了与人力相当的效果,但效率要高得多。根据我们的评估,我们确定了这些流行方案的设计缺陷、最佳实践和更安全的验证码的设计原则。
Nowadays, image captchas are being widely used across the Internet to defend against abusive programs. However, the ever-advancing capabilities of computer vision techniques are gradually diminishing the security of image captchas; yet, little is known thus far about the vulnerability of image captchas deployed in real-world settings. In this paper, we conduct the first systematic study on the security of image captchas in the wild. We classify the currently popular image captchas into three categories: selection-, slide- and click-based captchas. We propose three effective and generic attacks, each against one of these categories. We evaluate our attacks against 10 real-world popular image captchas, including those from tencent.com, google.com, and 12306.cn. Furthermore, we compare our attacks with 9 online image recognition services and human labors from 8 underground captcha-solving services. Our studies show that: (1) all of those popular image captchas are vulnerable to our attacks; (2) our attacks significantly outperform the state-of-the-arts in almost all the scenarios; and (3) our attacks achieve effectiveness comparable to human labors but with much higher efficiency. Based on our evaluation, we identify the design flaws of those popular schemes, the best practices, and the design principles towards more secure captchas.