The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern Web
Behzad Ousat, Esteban Schafir, Duc C. Hoang, Mohammad Ali Tofighi, Cuong V. Nguyen, Sajjad Arshad, A. Selcuk Uluagac, Amin Kharraz
摘要
The web ecosystem is a fast-paced environment. In this dynamic landscape, new security features are offered one after another to enhance the security and robustness of web applications and the operations they handle. This paper focuses on a fragile but still in-use security feature, text-based CAPTCHAs, that had been wildly used by web applications in the past to protect against automated attacks such as credential stuffing and automated account hijacking. The paper first investigates what it takes to develop automated scanners that can solve previously unseen text-based CAPTCHAs. To this end, we evaluated the possibility of developing and integrating a pre-trained CAPTCHA solver in the automated web scanning process without using a significantly large training dataset. We also performed an analysis of the impact of such autonomous scanners on CAPTCHA-enabled websites. Our analysis showed that using solvable text-based CAPTCHAs on login, contact, and comment pages of websites is not uncommon. In particular, we identified more than 3,000 text-based CAPTCHA websites in critical sectors such as finance, government, and health, involving hundreds of thousands of users. We showed that a web scanner with a pretrained solver could solve more than 20% of previously unseen CAPTCHAs in just one single attempt. This result is worrisome considering the substantial potential to autonomously run the operation across thousands of websites on a daily basis with minimal training. Furthermore, the finding suggests that the integration of autonomous scanning with pre-training and local optimization of models can significantly increase adversaries' asymmetric power to launch their attacks cheaper and faster.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper1
问问它们各自怎么用它它引用的顶会 Paper14
- Online Tracking: A 1-million-site Measurement and AnalysisSteven Englehardt, Arvind NarayananCCS 2016 · 被引用 798 次
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 被引用 279 次
- Yet Another Text Captcha Solver: A Generative Adversarial Network Based ApproachGuixin Ye, Zhanyong Tang, Dingyi Fang, Zhanxing Zhu 等CCS 2018 · 被引用 138 次
- A Simple Generic Attack on Text CaptchasHaichang Gao, Jeff Yan, Fang Cao, Zhengya Zhang 等NDSS 2016 · 被引用 106 次
- XHOUND: Quantifying the Fingerprintability of Browser ExtensionsOleksii Starov, Nick NikiforakisS&P 2017 · 被引用 104 次
相关 Paper
- A Generic Solver Combining Unsupervised Learning and Representation Learning for Breaking Text-Based CaptchasSheng Tian, Tao XiongWWW 2020 · 被引用 22 次
- Text Captcha Is Dead? A Large Scale Deployment and Empirical StudyChenghui Shi, Shouling Ji, Qianjun Liu, Changchang Liu 等CCS 2020 · 被引用 22 次
- GeeSolver: A Generic, Efficient, and Effortless Solver with Self-Supervised Learning for Breaking Text CaptchasRuijie Zhao, Xianwen Deng, Yanhao Wang, Zhicong Yan 等S&P 2023
- PassREfinder: Credential Stuffing Risk Prediction by Representing Password Reuse between Websites on a GraphJaehan Kim, Minkyoo Song, Minjae Seo, Youngjin Jin 等S&P 2024 · 被引用 8 次
- PhishDecloaker: Detecting CAPTCHA-cloaked Phishing Websites via Hybrid Vision-based Interactive ModelsXiwen Teoh, Yun Lin, Ruofan Liu, Zhiyong Huang 等USENIX Security 2024 · 被引用 13 次
