Emerging Image Game CAPTCHAs for Resisting Automated and Human-Solver Relay Attacks

Song Gao, Manar Mohamed, Nitesh Saxena, Chengcui Zhang
2015 Proceedings of the 31st Annual Computer Security Applications Conference on - ACSAC 2015  
CAPTCHAs represent an important pillar in the web security domain. Yet, current CAPTCHAs do not fully meet the web security requirements. Many existing CAPTCHAs can be broken using automated attacks based on image processing and machine learning techniques. Moreover, most existing CAPTCHAs are completely vulnerable to human-solver relay attacks, whereby CAPTCHA challenges are simply outsourced to a remote human solver. In this paper, we introduce a new class of CAPTCHAs that can not only resist
more » ... automated attacks but can also make relay attacks hard and detectable. These CAPTCHAs are carefully built on the notions of dynamic cognitive games (DCG) and emerging images (EI), present in the literature. While existing CAPTCHAs based on the DCG notion alone (e.g., an object matching game embedded in a clear background) are prone to automated attacks and those based on the EI notion alone (e.g., moving text embedded in emerging images) are prone to relay attacks, we show that a careful amalgamation of the two notions can resist both forms of attacks. Specifically, we formalize, design and implement a concrete instantiation of EI-DCG CAPTCHAs, and demonstrate its security with respect to image processing and object tracking techniques as well as their resistance to and detectability of relay attacks. Our Contributions: We introduce a new class of CAPTCHAs (called EI-DCG), carefully combining the EI and DCG notions, that can not only resist automated attacks but also make relay attacks hard and detectable. Our specific contributions are three-fold:
doi:10.1145/2818000.2818006 dblp:conf/acsac/GaoMSZ15 fatcat:hz5pm7weljdphejde4yx2jlevi