Dynamic Cognitive Game CAPTCHA Usability and Detection of Streaming-Based Farming

Dynamic Cognitive Game CAPTCHA Usability and Detection of Streaming-Based Farming
复制标题

动态认知游戏验证码可用性和流式农业检测

DOI:
--
复制
发表时间:
2014
期刊:
影响因子:
--
通讯作者:
Chengcui Zhang
Chengcui Zhang
中科院分区:
--
文献类型:
--
作者:
Manar Mohamed;Song Gao;Nitesh Saxena;Chengcui Zhang

文献摘要

被引文献

相似文献

CAPTCHA是一种广泛部署的机制,用于区分合法的人类用户和试图滥用在线服务的计算机程序。然而,攻击者已经设计了一种聪明而经济的方法,通过简单地将CAPTCHA挑战中继给远程人工求解器来绕过CAPTCHA提供的安全性。大多数现有的CAPTCHA品种完全容易受到这种中继攻击,通常在野外执行。动态认知游戏(DCG)CAPTCHA是一个新兴的CAPTCHA类别,要求用户玩一个简单的移动对象匹配游戏。由于底层游戏的动态性和交互性,DCG CAPTCHA可以抵抗中继攻击。在本文中,我们专注于基于流的DCG CAPTCHA中继攻击,其中游戏帧和响应简单地流之间的攻击者和人类求解器。我们提出了一种基于真实的游戏统计数据(例如游戏持续时间,鼠标点击和不正确的拖动)来检测这种支持流媒体的游戏验证码农业的机制,这些统计数据被馈送到机器学习检测算法。为了证明我们的检测机制的可行性,我们报告了一项三维研究,测量:(1)合法DCG CAPTCHA用户的性能,(2)DCG CAPTCHA流攻击中远程人类求解器的性能,以及(3)游戏行为特征和机器学习分类器在区分人类求解器和合法用户时的性能。我们的研究结果表明,它是可能的检测基于流的中继攻击对许多实例的DCG CAPTCHA具有较高的整体准确性(低误报和漏报)。一般来说,DCG CAPTCHA似乎是第一个能够可靠检测中继攻击的CAPTCHA方案之一。
CAPTCHAs are a widely deployed mechanism to distinguish a legitimate human user from a computerized pro- gram trying to abuse online services. Attackers, however, have devised a clever and an economical way to bypass the secu- rity provided by CAPTCHAs by simply relaying CAPTCHA challenges to remote human-solvers. Most existing varieties of CAPTCHAs are completely vulnerable to such relay attacks, routinely executed in the wild. Dynamic Cognitive Game (DCG) CAPTCHAs are an up- coming CAPTCHA category which require the user to play a simple moving object matching game. Due to the dynamic and interactive nature of the underlying games, DCG CAPTCHAs may offer resistance to relay attacks. In this paper, we focus on a streaming-based DCG CAPTCHA relay attack whereby the game frames and responses are simply streamed between the attacker and a human-solver. We present a mechanism for detecting such a streaming-enabled game captcha farming based on real- time game statistics, such as play duration, mouse clicks and incorrect drags, fed to machine learning detection algorithms. To demonstrate the feasibility of our detection mechanism, we report on a three-dimensional study measuring: (1) the performance of legitimate DCG CAPTCHA users, (2) the performance of remote human-solvers in a DCG CAPTCHA streaming attack, and (3) the performance of gameplay behavioral features and machine learning classifiers in distinguishing human-solvers in a streaming attack from legitimate users. Our results show that it is possible to detect the streaming-based relay attack against many instances of DCG CAPTCHAs with a high overall accuracy (low false negatives and false positives). Broadly, DCG CAPTCHAs appear to be one of the first CAPTCHA schemes that enable reliable detection of relay attacks.