vix.ing · top · new · best · stats

Three-Way Dissection of a Game-CAPTCHA: Automated Attacks, Relay Attacks, and Usability

2013/10/06 by Manar Mohamed, Niharika Sachdeva, Mohamed, Manar +15 · 15 citations
Computer Science · #Advanced Malware Detection Techniques #CAPTCHA #Computer science #Computer security #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Human-Computer Interaction (cs.HC) #Human–computer interaction #Relay #Spam and Phishing Detection #Usability #User Authentication and Security Systems #cs.CR #cs.HC

paper · pdf · doi:10.48550/arxiv.1310.1540

published in arXiv (Cornell University) (Cornell University) · 16 pages, 10 figures

arxiv created 2013/10/06 · openalex publication_date 2013/10/06 · arxiv updated 2013/10/09 · openalex created_date 2016/06/24 · openalex updated_date 2026/08/06

Abstract

Existing captcha solutions on the Internet are a major source of user frustration. Game captchas are an interesting and, to date, little-studied approach claiming to make captcha solving a fun activity for the users. One broad form of such captchas -- called Dynamic Cognitive Game (DCG) captchas -- challenge the user to perform a game-like cognitive task interacting with a series of dynamic images. We pursue a comprehensive analysis of a representative category of DCG captchas. We formalize, design and implement such captchas, and dissect them across: (1) fully automated attacks, (2) human-solver relay attacks, and (3) usability. Our results suggest that the studied DCG captchas exhibit high usability and, unlike other known captchas, offer some resistance to relay attacks, but they are also vulnerable to our novel dictionary-based automated attack.

Citations

Related