Security Analysis and Related Usability of Motion-Based CAPTCHAs: Decoding Codewords in Motion

被引:15
|
作者
Xu, Yi [1 ]
Reynaga, Gerardo [2 ]
Chiasson, Sonia [2 ]
Frahm, Jan-Michael [1 ]
Monrose, Fabian [1 ]
van Oorschot, Paul C. [2 ]
机构
[1] Univ N Carolina, Dept Comp Sci, Chapel Hill, NC 27515 USA
[2] Carleton Univ, Sch Comp Sci, Ottawa, ON K1S 5B6, Canada
基金
美国国家科学基金会; 加拿大自然科学与工程研究理事会;
关键词
CAPTCHAs; security; usability; computer vision; SEGMENTATION;
D O I
10.1109/TDSC.2013.52
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
We explore the robustness and usability of moving-image object recognition (video) captchas, designing and implementing automated attacks based on computer vision techniques. Our approach is suitable for broad classes of moving-image captchas involving rigid objects. We first present an attack that defeats instances of such a captcha (NuCaptcha) representing the state-of-the-art, involving dynamic text strings called codewords. We then consider design modifications to mitigate the attacks (e.g., overlapping characters more closely, randomly changing the font of individual characters, or even randomly varying the number of characters in the codeword). We implement the modified captchas and test if designs modified for greater robustness maintain usability. Our lab-based studies show that the modified captchas fail to offer viable usability, even when the captcha strength is reduced below acceptable targets. Worse yet, our GPU-based implementation shows that our automated approach can decode these captchas faster than humans can, and we can do so at a relatively low cost of roughly 50 cents per 1,000 captchas solved based on Amazon EC2 rates circa 2012. To further demonstrate the challenges in designing usable captchas, we also implement and test another variant of moving text strings using the known emerging images concept. This variant is resilient to our attacks and also offers similar usability to commercially available approaches. We explain why fundamental elements of the emerging images idea resist our current attack where others fail.
引用
收藏
页码:480 / 493
页数:14
相关论文
共 50 条
  • [1] Usability Evaluation of a Leap Motion-Based Educational Application
    Al-Razooq, Arwa
    Boreggah, Bayan
    Al-Qahtani, Laila
    Jafri, Rabia
    [J]. ADVANCES IN HUMAN FACTORS, BUSINESS MANAGEMENT, TRAINING AND EDUCATION, 2017, 498 : 171 - 185
  • [2] Motion-based motion deblurring
    Ben-Ezra, M
    Nayar, SK
    [J]. IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2004, 26 (06) : 689 - 698
  • [3] Motion-Based Analysis of Dynamic Textures - A Survey
    Bida, Ikram
    Aouat, Saliha
    [J]. ADVANCES IN COMPUTING SYSTEMS AND APPLICATIONS, 2019, 50 : 182 - 192
  • [4] Motion-Based Analysis and Synthesis of Dynamic Textures
    Chubach, Olena
    Garus, Patrick
    Wien, Mathias
    [J]. 2016 PICTURE CODING SYMPOSIUM (PCS), 2016,
  • [5] Motion-based colour integration in ambiguous motion
    Watanabe, J.
    Nishida, S.
    [J]. PERCEPTION, 2006, 35 : 195 - 195
  • [6] Invariants for motion-based classification
    Hafez, W
    [J]. EXPLOITING NEW IMAGE SOURCES AND SENSORS, 26TH AIPR WORKSHOP, 1998, 3240 : 341 - 350
  • [7] MOTION-BASED RECOGNITION - A SURVEY
    CEDRAS, C
    SHAH, M
    [J]. IMAGE AND VISION COMPUTING, 1995, 13 (02) : 129 - 155
  • [8] Motion-based treatment delivery
    Boldrini, L.
    [J]. RADIOTHERAPY AND ONCOLOGY, 2020, 152 : S422 - S422
  • [9] A Motion-Based Communication System
    Jones, Austin
    Andersson, Sean
    [J]. 2013 AMERICAN CONTROL CONFERENCE (ACC), 2013, : 365 - 370
  • [10] Motion-based recognition of pedestrians
    Heisele, B
    Wohler, C
    [J]. FOURTEENTH INTERNATIONAL CONFERENCE ON PATTERN RECOGNITION, VOLS 1 AND 2, 1998, : 1325 - 1330