BASECASS: A methodology for CAPTCHAs security assurance

被引:2
|
作者
Hernandez-Castro, Carlos Javier [1 ]
Barrero, David F. [1 ]
R-Moreno, Maria D. [1 ]
机构
[1] Univ Alcala, Escuela Politecn Super, ISG, Alcala De Henares, Spain
关键词
CAPTCHA; Methodology; Machine Learning; Statistical analysis; Security assurance;
D O I
10.1016/j.jisa.2021.103018
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Today, much of the interaction between clients and providers has moved to the Internet. Some tricksters have also learned to benefit from this new situation. New improved cons, tricks and deceptions can be found on-line. Many of these deceptions are only profitable if they are done at a large scale. In order to achieve these large numbers of interactions, these attacks require automation. CAPTCHAs/HIPs are a relatively new security mechanism against automated attacks. They try to detect when the other end of the interaction is a human or a computer program (a bot). However, CAPTCHA/HIP design is still in its initial conception as the stream of successful attacks highlight it. This paper focuses on the design of CAPTCHAs and if there is a way in which to assess a basic level of security for new CAPTCHA designs. To do so, we first review main attacks to different types of CAPTCHAs and then, we describe BASECASS, a methodology that can help in avoiding some of these design pitfalls. The application of the methodology is exemplified in three attacks to CAPTCHAs and how following the methodology designers could have avoided them.
引用
收藏
页数:15
相关论文
共 50 条
  • [41] Quality assurance in trichiasis surgery: a methodology
    Buchan, John C.
    Limburg, Hans
    Burton, Matthew J.
    BRITISH JOURNAL OF OPHTHALMOLOGY, 2011, 95 (03) : 331 - 334
  • [42] Assurance Methodology for In-vehicle AI
    Blank, Frédérik
    Hüger, Fabian
    Mock, Michael
    Stauner, Thomas
    ATZ worldwide, 2022, 124 (7-8) : 54 - 59
  • [43] Methodology of quality assurance in Polish industries
    Kindlarski, E.
    Quality Forum, 1992, 18 (04):
  • [44] Assurance of Information Systems' Quality and Security
    Izonin, Ivan
    Hovorushchenko, Tetiana
    Popov, Peter
    Journal of Cyber Security and Mobility, 2023, 12 (03):
  • [45] Security Assurance Against Cybercrime Ransomware
    Rehman, Habib Ur
    Yafi, Eiad
    Nazir, Mohammed
    Mustafa, Khurram
    INTELLIGENT COMPUTING & OPTIMIZATION, 2019, 866 : 21 - 34
  • [46] Intelligent manufacturing system and security and assurance
    Park, Jong Hyuk
    Zou, Deqing
    Kim, Tai-hoon
    Lopez, Javier
    Chang, Hangbae
    JOURNAL OF INTELLIGENT MANUFACTURING, 2010, 21 (05) : 593 - 594
  • [47] Assurance: the power behind PCASSO security
    Baker, DB
    Masys, DR
    Jones, RL
    Barnhart, RM
    JOURNAL OF THE AMERICAN MEDICAL INFORMATICS ASSOCIATION, 1999, : 666 - 670
  • [48] Sustainable wireless clouds with security assurance
    Sathish K.
    Kolli K.
    Sathish, Kuppani (skuppani@gmail.com), 1600, Inderscience Publishers (14): : 146 - 159
  • [49] Cyber Mission Assurance for Cyber Security
    MacKay M.
    ITNOW, 2020, 62 (01) : 32 - 33
  • [50] Embracing the Diversity of Information Assurance & Security
    Myers, J. Paul, Jr.
    Riela, Sandra
    IMSCI '08: 2ND INTERNATIONAL MULTI-CONFERENCE ON SOCIETY, CYBERNETICS AND INFORMATICS, VOL 1, PROCEEDINGS, 2008, : 215 - +