CAPTCHA security: A case study
CAPTCHA security: A case study
A Case Study on Completely Automated Public Turing Tests to Tell Computers and Humans Apart (CAPTCHA) security systems is presented. CAPTCHA generate and grade tests that most humans can pass but current computer programs are not able to pass and such tests are called as CAPTCHA challenges that are based on hard, open artificial intelligence problems. CAPTCHA creators should consider the simple but powerful attack before deploying a CAPTCHA. CAPTCHA will go through the process of evolutionary development such as cryptography, digital watermarking, and an iterative process in which successful attacks lead to the development of more robust systems. CAPTCHA's robustness that whether it is robust enough to resist adversarial attack should be checked. A toolbox should be created that will be able to not only benchmark CAPTCHA's strength but also prevent designers from making mistakes.
CAPTCHA, Dictionary attacks, Pixel count, Security
22-28
Yan, Jeff
a2c03187-3722-46c8-b73b-439eb9d1a10e
El Ahmad, Ahmad Salah
e6e3d56d-a029-404f-aca6-14a8d54d2f43
2009
Yan, Jeff
a2c03187-3722-46c8-b73b-439eb9d1a10e
El Ahmad, Ahmad Salah
e6e3d56d-a029-404f-aca6-14a8d54d2f43
Yan, Jeff and El Ahmad, Ahmad Salah
(2009)
CAPTCHA security: A case study.
IEEE Security and Privacy, 7 (4), , [5189558].
(doi:10.1109/MSP.2009.84).
Abstract
A Case Study on Completely Automated Public Turing Tests to Tell Computers and Humans Apart (CAPTCHA) security systems is presented. CAPTCHA generate and grade tests that most humans can pass but current computer programs are not able to pass and such tests are called as CAPTCHA challenges that are based on hard, open artificial intelligence problems. CAPTCHA creators should consider the simple but powerful attack before deploying a CAPTCHA. CAPTCHA will go through the process of evolutionary development such as cryptography, digital watermarking, and an iterative process in which successful attacks lead to the development of more robust systems. CAPTCHA's robustness that whether it is robust enough to resist adversarial attack should be checked. A toolbox should be created that will be able to not only benchmark CAPTCHA's strength but also prevent designers from making mistakes.
This record has no associated files available for download.
More information
Published date: 2009
Keywords:
CAPTCHA, Dictionary attacks, Pixel count, Security
Identifiers
Local EPrints ID: 504141
URI: http://eprints.soton.ac.uk/id/eprint/504141
ISSN: 1540-7993
PURE UUID: d0482daf-78ba-41bd-a57e-d184a673fd7f
Catalogue record
Date deposited: 27 Aug 2025 16:49
Last modified: 27 Aug 2025 16:49
Export record
Altmetrics
Contributors
Author:
Jeff Yan
Author:
Ahmad Salah El Ahmad
Download statistics
Downloads from ePrints over the past year. Other digital versions may also be available to download e.g. from the publisher's website.
View more statistics