BASECASS: A methodology for CAPTCHAs security assurance

被引:2
|
作者
Hernandez-Castro, Carlos Javier [1 ]
Barrero, David F. [1 ]
R-Moreno, Maria D. [1 ]
机构
[1] Univ Alcala, Escuela Politecn Super, ISG, Alcala De Henares, Spain
关键词
CAPTCHA; Methodology; Machine Learning; Statistical analysis; Security assurance;
D O I
10.1016/j.jisa.2021.103018
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today, much of the interaction between clients and providers has moved to the Internet. Some tricksters have also learned to benefit from this new situation. New improved cons, tricks and deceptions can be found on-line. Many of these deceptions are only profitable if they are done at a large scale. In order to achieve these large numbers of interactions, these attacks require automation. CAPTCHAs/HIPs are a relatively new security mechanism against automated attacks. They try to detect when the other end of the interaction is a human or a computer program (a bot). However, CAPTCHA/HIP design is still in its initial conception as the stream of successful attacks highlight it. This paper focuses on the design of CAPTCHAs and if there is a way in which to assess a basic level of security for new CAPTCHA designs. To do so, we first review main attacks to different types of CAPTCHAs and then, we describe BASECASS, a methodology that can help in avoiding some of these design pitfalls. The application of the methodology is exemplified in three attacks to CAPTCHAs and how following the methodology designers could have avoided them.
引用
收藏
页数:15
相关论文
共 50 条
  • [21] mCaptcha: Replacing Captchas with Rate Limiters to Improve Security and Accessibility
    Manivannan, Aravinth
    Sethuraman, Sibi Chakkaravarthy
    Sudhakaran, Devi Priya Vimala
    COMMUNICATIONS OF THE ACM, 2024, 67 (10) : 70 - 80
  • [22] Software assurance for security
    McGraw, G
    COMPUTER, 1999, 32 (04) : 103 - 105
  • [23] Search for assurance and security
    Burger, Rudolf
    MERKUR-DEUTSCHE ZEITSCHRIFT FUR EUROPAISCHES DENKEN, 2007, 61 (04): : 324 - 332
  • [24] Towards Evaluating the Security of Real-World Deployed Image CAPTCHAs
    Zhao, Binbin
    Weng, Haiqin
    Ji, Shouling
    Chen, Jianhai
    Wang, Ting
    He, Qinming
    Beyah, Raheem
    AISEC'18: PROCEEDINGS OF THE 11TH ACM WORKSHOP ON ARTIFICIAL INTELLIGENCE AND SECURITY, 2018, : 85 - 96
  • [25] Security assurance for an RBAC/MAC security model
    Phillips, CE
    Demurjian, SA
    Ting, TC
    IEEE SYSTEMS, MAN AND CYBERNETICS SOCIETY INFORMATION ASSURANCE WORKSHOP, 2003, : 260 - 267
  • [26] MICROBIOLOGY - METHODOLOGY AND QUALITY ASSURANCE
    BORDNER, RH
    JOURNAL WATER POLLUTION CONTROL FEDERATION, 1981, 53 (06): : 1098 - 1107
  • [27] MICROBIOLOGY - METHODOLOGY AND QUALITY ASSURANCE
    BORDNER, RH
    JOURNAL WATER POLLUTION CONTROL FEDERATION, 1983, 55 (06): : 881 - 890
  • [28] MICROBIOLOGY - METHODOLOGY AND QUALITY ASSURANCE
    BORDNER, RH
    JOURNAL WATER POLLUTION CONTROL FEDERATION, 1982, 54 (06): : 1024 - 1037
  • [29] Development of two novel face-recognition CAPTCHAs: A security and usability study
    Schryen, Guido
    Wagner, Gerit
    Schlegel, Alexander
    COMPUTERS & SECURITY, 2016, 60 : 95 - 116
  • [30] Security Assurance for Smart Contract
    Zhou, Ence
    Hua, Song
    Pi, Bingfeng
    Sun, Jun
    Nomura, Yashihide
    Yamashita, Kazuhiro
    Kurihara, Hidetoshi
    2018 9TH IFIP INTERNATIONAL CONFERENCE ON NEW TECHNOLOGIES, MOBILITY AND SECURITY (NTMS), 2018,