All about uncertainties and traps: Statistical oracle-based attacks on a new CAPTCHA protection against oracle attacks

被引:4
|
作者
Javier Hernandez-Castro, Carlos [1 ]
Li, Shujun [3 ]
R-Moreno, Maria D. [2 ]
机构
[1] Univ Alcala, Madrid, Spain
[2] Univ Alcala, Artificial Intelligence, Madrid, Spain
[3] Univ Kent, Cyber Secur, Canterbury, Kent, England
基金
英国工程与自然科学研究理事会;
关键词
CAPTCHA; Uncertainty; Trap images; Machine learning; Image classification; Oracle attacks; Statistical attacks;
D O I
10.1016/j.cose.2020.101758
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
CAPTCHAs are security mechanisms that try to prevent automated abuse of computer services. Many CAPTCHAs have been proposed but most have known security flaws against advanced attacks. In order to avoid a kind of oracle attacks in which the attacker learns about ground truth labels via active interactions with the CAPTCHA service as an oracle, Kwon and Cha proposed a new CAPTCHA scheme that employ uncertainties and trap images to generate adaptive CAPTCHA challenges, which we call "Uncertainty and Trap Strengthened CAPTCHA"(UTS-CAPTCHA) in this paper. Adaptive CAPTCHA challenges are used widely (either explicitly or implicitly) but the role of such adaptive mechanisms in the security of CAPTCHAs has received little attention from researchers. In this paper we present a statistical fundamental design flaw of UTS-CAPTCHA. This flaw leaks information regarding ground truth labels of images used. Exploiting this flaw, an attacker can use the UTS-CAPTCHA service as an oracle, and perform several different statistical learning-based attacks against UTS-CAPTCHA, increasing any reasonable initial success rate up to 100% according to our theoretical estimation and experimental simulations. Based on our proposed attacks, we discuss how the fundamental idea behind our attacks may be generalized to attack other CAPTCHA schemes and propose a new principle and a number of concrete guidelines for designing new CAPTCHA schemes in the future. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:12
相关论文
共 3 条
  • [1] Oracle-based Logic Locking Attacks: Protect the Oracle Not Only the Netlist
    Kalligeros, Emmanouil
    Karousos, Nikolaos
    Karybali, Irene G.
    PROCEEDINGS OF THE 2020 DESIGN, AUTOMATION & TEST IN EUROPE CONFERENCE & EXHIBITION (DATE 2020), 2020, : 939 - 944
  • [2] TaintLock: Hardware IP Protection Against Oracle-Guided and Oracle-Reconstruction Attacks
    Talukdar, Jonti
    Chaudhuri, Arjun
    Ortega, Eduardo
    Chakrabarty, Krishnendu
    IEEE TRANSACTIONS ON COMPUTER-AIDED DESIGN OF INTEGRATED CIRCUITS AND SYSTEMS, 2025, 44 (01) : 357 - 370
  • [3] A BIST-based Dynamic Obfuscation Scheme for Resilience against Removal and Oracle-guided Attacks
    Talukdar, Jonti
    Chen, Siyuan
    Das, Amitabh
    Aftabjahani, Sohrab
    Song, Peilin
    Chakrabarty, Krishnendu
    2021 IEEE INTERNATIONAL TEST CONFERENCE (ITC 2021), 2021, : 170 - 179