All about uncertainties and traps: Statistical oracle-based attacks on a new CAPTCHA protection against oracle attacks

All about uncertainties and traps: Statistical oracle-based attacks on a new CAPTCHA protection against oracle attacks
复制标题

关于不确定性和陷阱:基于统计预言机的攻击,针对新的验证码防范预言机攻击

DOI:
10.1016/j.cose.2020.101758
复制
发表时间:
2020
影响因子:
5.6
通讯作者:
Hernández-Castro C
Hernández-Castro C
中科院分区:
计算机科学3区
文献类型:
--
作者:
Hernández-Castro C

文献摘要

参考文献

相似文献

CAPTCHA是一种安全机制,试图防止计算机服务的自动滥用。已经提出了许多CAPTCHA,但大多数都有针对高级攻击的已知安全缺陷。为了避免攻击者通过与CAPTCHA服务的主动交互来学习真实标签的预言攻击,Kwon和Cha提出了一种新的CAPTCHA方案,该方案利用不确定性和陷阱图像来生成自适应的CAPTCHA挑战,我们称之为“不确定性和陷阱增强的CAPTCHA”(UTS-CAPTCHA)。自适应CAPTCHA挑战被广泛使用(显式或隐式),但这种自适应机制在CAPTCHA安全性中的作用却很少受到研究人员的关注。该漏洞泄漏了有关所用图像的地面真实标签的信息。利用这个漏洞,攻击者可以使用UTS-CAPTCHA服务作为预言机,并对UTS-CAPTCHA执行几种不同的基于统计学习的攻击,根据我们的理论估计和实验模拟,将任何合理的初始成功率提高到100%。基于我们提出的攻击,我们讨论了我们的攻击背后的基本思想如何可以推广到攻击其他CAPTCHA计划,并提出了一个新的原则和一些具体的指导方针,为设计新的CAPTCHA计划在未来。
CAPTCHAs are security mechanisms that try to prevent automated abuse of computer services. Many CAPTCHAs have been proposed but most have known security flaws against advanced attacks. In order to avoid a kind of oracle attacks in which the attacker learns about ground truth labels via active interactions with the CAPTCHA service as an oracle, Kwon and Cha proposed a new CAPTCHA scheme that employ uncertainties and trap images to generateadaptiveCAPTCHA challenges, which we call “Uncertainty and Trap Strengthened CAPTCHA” (UTS-CAPTCHA) in this paper. Adaptive CAPTCHA challenges are used widely (either explicitly or implicitly) but the role of such adaptive mechanisms in the security of CAPTCHAs has received little attention from researchers.In this paper we present a statistical fundamental design flaw of UTS-CAPTCHA. This flaw leaks information regarding ground truth labels of images used. Exploiting this flaw, an attacker can use the UTS-CAPTCHA service as an oracle, and perform several different statistical learning-based attacks against UTS-CAPTCHA, increasing any reasonable initial success rate up to 100% according to our theoretical estimation and experimental simulations. Based on our proposed attacks, we discuss how the fundamental idea behind our attacks may be generalized to attack other CAPTCHA schemes and propose a new principle and a number of concrete guidelines for designing new CAPTCHA schemes in the future.
重新审视 2F 方法的安全分析
DOI: --
发表时间: 2023
期刊:
影响因子: --
作者:
Hiroaki Motohashi;Kien Nguyen;Hiroo Sekiya;池松泰彦
通讯作者: 池松泰彦
幸运饼干和智能手机:对抗中继攻击的弱不可中继通道
DOI: --
发表时间: 2015
影响因子: 4.3
作者:
Mario Cagalj;T. Perković;M. Bugarić;Shujun Li
通讯作者: Shujun Li
验证码在哪里失败:验证码设计中常见陷阱以及如何避免它们的研究
DOI: --
发表时间: 2017
期刊:
影响因子: --
作者:
Carlos Javier Hernández Castro
通讯作者: Carlos Javier Hernández Castro
完全自动化的公共物理测试来区分计算机和人类:移动设备的可用性研究
DOI: --
发表时间: 2017
期刊: Future generations computer systems
影响因子: --
作者:
Meriem Guerar;A. Merlo;M. Migliardi
通讯作者: M. Migliardi
DOI: 10.1109/tifs.2017.2718479
发表时间: 2017-06
影响因子: 6.8
作者:
Margarita Osadchy;Julio Hernandez-Castro;S. Gibson;O. Dunkelman;Daniel Pérez-Cabo
通讯作者: Margarita Osadchy;Julio Hernandez-Castro;S. Gibson;O. Dunkelman;Daniel Pérez-Cabo