The robustness of behavior-verification-based slider CAPTCHAs

Guoqin Chang,Haichang Gao,Ge Pei,Sainan Luo,Yang Zhang,Nuo Cheng,Yiwen Tang,Qianwen Guo
DOI: https://doi.org/10.1016/j.jisa.2024.103711
IF: 4.96
2024-02-01
Journal of Information Security and Applications
Abstract:CAPTCHAs represent a vital technique for protecting the security of websites by differentiating between humans and bots. There have been many successful attacks against text and image CAPTCHAs, demonstrating that they are no longer secure, and blindly using methods to enhance CAPTCHAs robustness may reduce user-friendliness. Slider CAPTCHAs, which are based on behavioral verification, are being used on more and more websites as an alternative to text CAPTCHAs and image CAPTCHAs. However, despite the widespread use of slider CAPTCHAs, their security remains largely unknown. In this paper, we introduce a simple, efficient and generic approach for attacking five widely deployed slider CAPTCHAs, with success rates ranging from 87.5% to 100%. Experimental results proving that behavior-verification-based slider CAPTCHAs do not fully differentiate between humans and bots, especially with regard to mouse operation behavior. Simultaneously, this paper also discusses whether deep learning technology can further improve the security of slider CAPTCHAs by analyzing user behavior trajectories, hoping that our work can provide new inspiration for designers to design more effective CAPTCHAs.
computer science, information systems
What problem does this paper attempt to address?