Using automatic speech recognition for attacking acoustic CAPTCHAs: the trade-off between usability and security

Using automatic speech recognition for attacking acoustic CAPTCHAs: the trade-off between usability and security
复制标题

使用自动语音识别攻击声学验证码:可用性和安全性之间的权衡

DOI:
10.1145/2664243.2664262
复制
发表时间:
2014
期刊:
Proceedings of the 30th Annual Computer Security Applications Conference
影响因子:
--
通讯作者:
Dorothea Kolossa
Dorothea Kolossa
中科院分区:
--
文献类型:
--
作者:
Hendrik Meutzner;Viet-Hung Nguyen;Thorsten Holz;Dorothea Kolossa

文献摘要

参考文献

被引文献

相似文献

防止自动滥用互联网服务的一种常见方法是利用挑战-响应测试来区分人类用户和机器。这些测试被称为CAPTCHA(完全自动化的公共图灵测试,以区分计算机和人类),应该代表一个对人类来说很容易解决的任务,但对欺诈程序来说很难。为了使视力受损的人能够访问,除了更知名的视觉CAPTCHA之外,通常还提供声学CAPTCHA。最近的安全研究表明,大多数声学CAPTCHA,虽然很难解决的人,可以通过机器学习打破。在这项工作中,我们建议使用语音识别,而不是一般的分类方法,以更好地分析声学CAPTCHA的安全性。结果表明,基于自动语音识别系统的攻击可以成功地击败reCAPTCHA,成功率明显高于以往的研究。设计CAPTCHA的一个主要困难是在人类可用性和对自动攻击的鲁棒性之间进行权衡。我们提出并分析了另一种CAPTCHA设计,它利用了人类听觉系统的特定功能,即,听觉流和对混响的耐受性。由于最先进的语音识别技术仍然没有提供这些功能,因此很难自动解决由此产生的CAPTCHA。对所提出的CAPTCHA的详细分析表明,与目前的准标准方法reCAPTCHA相比,它在可用性和安全性之间有更好的权衡。
A common method to prevent automated abuses of Internet services is utilizing challenge-response tests that distinguish human users from machines. These tests are known as CAPTCHAs (Completely Automated Public Turing Tests to Tell Computers and Humans Apart) and should represent a task that is easy to solve for humans, but difficult for fraudulent programs. To enable access for visually impaired people, an acoustic CAPTCHA is typically provided in addition to the better-known visual CAPTCHAs. Recent security studies show that most acoustic CAPTCHAs, albeit difficult to solve for humans, can be broken via machine learning.In this work, we suggest using speech recognition rather than generic classification methods for better analyzing the security of acoustic CAPTCHAs. We show that our attack based on an automatic speech recognition system can successfully defeat reCAPTCHA with a significantly higher success rate than reported in previous studies.A major difficulty in designing CAPTCHAs arises from the trade-off between human usability and robustness against automated attacks. We present and analyze an alternative CAPTCHA design that exploits specific capabilities of the human auditory system, i.e., auditory streaming and tolerance to reverberation. Since state-of-the-art speech recognition technology still does not provide these capabilities, the resulting CAPTCHA is hard to solve automatically. A detailed analysis of the proposed CAPTCHA shows a far better trade-off between usability and security than the current quasi-standard approach of reCAPTCHA.
改进的验证码方法
DOI: --
发表时间: 2010
期刊:
影响因子: --
作者:
R. Soni;Devendra Tiwari
通讯作者: Devendra Tiwari
提高听觉验证码安全性
DOI: --
发表时间: 2008
期刊:
影响因子: --
作者:
S. Bohr;Andrea Shome;J. Simon
通讯作者: J. Simon
DOI: --
发表时间: 2004
期刊:
影响因子: --
作者:
Nelson Mogran;H. Bourlard;H. Hermansky
通讯作者: H. Hermansky