- Security '12 Home
- Registration Information
- Registration Discounts
- Organizers
- At a Glance
- Calendar
- Technical Sessions
- Workshops
- Hotel & Travel Information
- Poster Session
- Rump Session
- Birds-of-a-Feather Sessions
- Sponsors
- Activities
- Students
- Questions?
- For Participants
- Help Promote
- Call for Papers
- Past Proceedings
sponsors
usenix conference policies
You are here
Security and Usability Challenges of Moving-Object CAPTCHAs: Decoding Codewords in Motion
Y. Xu, University of North Carolina at Chapel Hill; G. Reynaga and S. Chiasson, Carleton University; J.-M. Frahm and F. Monrose, University of North Carolina at Chapel Hill; P. van Oorschot, Carleton University
We explore the robustness and usability of moving-image object recognition (video) captchas, designing and implementing automated attacks based on computer vision techniques. Our approach is suitable for broad classes of moving-image captchas involving rigid objects. We first present an attack that defeats instances of such a captcha (NuCaptcha) representing the state-of-the-art, involving dynamic text strings called codewords. We then consider design modifications to mitigate the attacks (e.g., overlapping characters more closely). We implement the modified captchas and test if designs modified for greater robustness maintain usability. Our lab-based studies show that the modified captchas fail to offer viable usability, even when the captcha strength is reduced below acceptable targets—signaling that the modified designs are not viable. We also implement and test another variant of moving text strings using the known emerging images idea. This variant is resilient to our attacks and also offers similar usability to commercially available approaches. We explain why fundamental elements of the emerging images concept resist our current attack where others fails.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Y Xu and G Reynaga and Sonia Chiasson and J.-M. Frahm and Fabian Monrose and Paul van Oorschot},
title = {Security and Usability Challenges of {Moving-Object} {CAPTCHAs}: Decoding Codewords in Motion},
booktitle = {21st USENIX Security Symposium (USENIX Security 12)},
year = {2012},
isbn = {978-931971-95-9},
address = {Bellevue, WA},
pages = {49--64},
url = {https://www.usenix.org/conference/usenixsecurity12/technical-sessions/presentation/xu_y},
publisher = {USENIX Association},
month = aug
}
connect with us