Breaking e-Banking CAPTCHAs

被引:0
|
作者
Li, Shujun [1 ]
Shah, S. Amier Haider [2 ]
Khan, M. Asad Usman [2 ]
Khayam, Syed Ali [2 ]
Sadeghi, Ahmad-Reza [3 ]
Schmitz, Roland [4 ]
机构
[1] Univ Konstanz, Constance, Germany
[2] Natl Univ Sci & Technol, Islamabad, Pakistan
[3] Ruhr Univ Bochum, Bochum, Germany
[4] Stuttgart Media Univ, Stuttgart, Germany
关键词
CAPTCHA; e-banking; man-in-the-middle attack; malware;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Many financial institutions have deployed CAPTCHAs to protect their services (e.g., e-banking) from automated attacks. In addition to CAPTCHAs for login, CAPTCHAs are also used to prevent malicious manipulation of e-banking transactions by automated Man-in-the-Middle (MitM) attackers. Despite serious financial risks, security of e-banking CAPTCHAs is largely unexplored. In this paper, we report the first comprehensive study on e-banking CAPTCHAs deployed around the world. A new set of image processing and pattern recognition techniques is proposed to break all e-banking CAPTCHA schemes that we found over the Internet, including three e-banking CAPTCHA schemes for transaction veri fication and 41 schemes for login. These broken e-banking CAPTCHA schemes are used by thousands of financial institutions worldwide, which are serving hundreds of millions of e-banking customers. The success rate of our proposed attacks are either equal to or close to 100%. We also discuss possible improvements to these e-banking CAPTCHA schemes and show essential difficulties of designing e-banking CAPTCHAs that are both secure and usable.
引用
收藏
页码:171 / 180
页数:10
相关论文
共 50 条
  • [1] E-banking in Jordan
    Abbad, Muneer M.
    [J]. BEHAVIOUR & INFORMATION TECHNOLOGY, 2013, 32 (07) : 681 - 694
  • [2] Unsecure e-banking
    不详
    [J]. NEW SCIENTIST, 2010, 205 (2748) : 27 - 27
  • [3] Try E-banking
    Darlin, D
    [J]. FORBES, 1997, 159 (01): : 68 - 69
  • [4] E-banking in the context of banking changes
    Smalskys, Ugnius
    [J]. Changes in Social and Business Environment, 2006, : 204 - 209
  • [5] E-BANKING IMPLEMENTATION IN SERBIA
    Radojevic, Tijana
    Radovanovic, Dalibor
    [J]. 6TH INTERNATIONAL SCIENTIFIC CONFERENCE BUSINESS AND MANAGEMENT 2010, VOLS I AND II, 2010, : 936 - 942
  • [6] Current issues in e-banking
    Dewan, R
    Seidmann, A
    [J]. COMMUNICATIONS OF THE ACM, 2001, 44 (06) : 31 - 32
  • [7] The determinants of satisfaction with e-banking
    Liebana-Cabanillas, Francisco
    Munoz-Leiva, Francisco
    Rejon-Guardia, Francisco
    [J]. INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2013, 113 (05) : 750 - 767
  • [8] Challenges to Internet e-banking
    Liao, ZQ
    Cheung, MT
    [J]. COMMUNICATIONS OF THE ACM, 2003, 46 (12) : 248 - 250
  • [9] E-Banking: Issues and Challenges
    Nami, Mohammad Reza
    [J]. SNPD 2009: 10TH ACIS INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ARTIFICIAL INTELLIGENCES, NETWORKING AND PARALLEL DISTRIBUTED COMPUTING, PROCEEDINGS, 2009, : 263 - 266
  • [10] Usability and trust in e-banking
    Pravettoni, Gabriella
    Leotta, Salvatore Nuccio
    Lucchiari, Claudio
    Misuraca, Raffaella
    [J]. PSYCHOLOGICAL REPORTS, 2007, 101 (03) : 1118 - 1124