A low-cost attack on a Microsoft captcha

A low-cost attack on a Microsoft captcha
复制标题

DOI:
10.1145/1455770.1455839
复制
发表时间:
2008-10
期刊:
Proceedings of the 15th ACM conference on Computer and communications security
影响因子:
--
通讯作者:
Jeff Yan;A. S. E. Ahmad
Jeff Yan;A. S. E. Ahmad
中科院分区:
其他
文献类型:
--
作者:
Jeff Yan;A. S. E. Ahmad

文献摘要

被引文献

相似文献

CAPTCHA现在几乎是一种标准的安全技术。部署最广泛的captcha是基于文本的方案,通常要求用户解决文本识别任务。从目前的CAPTCHA设计水平来看,这种基于文本的方案应该依靠抗分割性来提供安全保障,因为分割后的个人字符识别可以通过神经网络等标准方法来解决,成功率很高。在本文中,我们提出了新的具有普遍价值的字符分割技术来攻击一些文本captcha,包括由Microsoft, Yahoo和b谷歌设计和部署的方案。特别是,自2002年以来,微软的许多在线服务都部署了验证码,包括Hotmail、MSN和Windows Live。为了防止分割,这个方案经过了多年的研究和调整。然而,我们的简单攻击对该方案的分割成功率高于90%。在一台普通的台式计算机上,完全分割一个挑战平均需要80毫秒。因此,我们估计这个CAPTCHA可以被恶意机器人立即破解,其总体(分割然后识别)成功率超过60%。相反,设计目标是自动攻击的成功率不应高于0.01%。本文首次表明,经过精心设计的防分割captcha容易受到新颖但简单的攻击。
CAPTCHA is now almost a standard security technology. The most widely deployed CAPTCHAs are text-based schemes, which typically require users to solve a text recognition task. The state of the art of CAPTCHA design suggests that such text-based schemes should rely on segmentation resistance to provide security guarantee, as individual character recognition after segmentation can be solved with a high success rate by standard methods such as neural networks. In this paper, we present new character segmentation techniques of general value to attack a number of text CAPTCHAs, including the schemes designed and deployed by Microsoft, Yahoo and Google. In particular, the Microsoft CAPTCHA has been deployed since 2002 at many of their online services including Hotmail, MSN and Windows Live. Designed to be segmentation-resistant, this scheme has been studied and tuned by its designers over the years. However, our simple attack has achieved a segmentation success rate of higher than 90% against this scheme. It took on average ~80 ms for the attack to completely segment a challenge on an ordinary desktop computer. As a result, we estimate that this CAPTCHA could be instantly broken by a malicious bot with an overall (segmentation and then recognition) success rate of more than 60%. On the contrary, the design goal was that automated attacks should not achieve a success rate of higher than 0.01%. For the first time, this paper shows that CAPTCHAs that are carefully designed to be segmentation-resistant are vulnerable to novel but simple attacks.