Abstract
CAPTCHA is a standard defence mechanism against bots, or automated programs, that attempt to use web-based services meant for human users. While there are many different types of CAPTCHA schemes that have emerged over the years, to date, the most widely used type is 2D text-based CAPTCHAs. Unfortunately, a large number of 2D CAPTCHA schemes have been successfully broken. Thus, 3D-based CAPTCHAs are seen as an alternative paradigm which has been explored by a number of CAPTCHA designers. 3D CAPTCHAs are meant to overcome the limitations of 2D CAPTCHAs and are supposed to be more robust and secure against automated attacks. To investigate the robustness of 3D text-based CAPTCHAs, this paper presents an approach to breaking a representative 3D CAPTCHA scheme called Teabag 3D. In particular, this paper describes the techniques that were used to break this CAPTCHA, and as such highlights various security issues that have to be considered in order to design better 3D CAPTCHA schemes.
Access this chapter
Tax calculation will be finalised at checkout
Purchases are for personal use only
Preview
Unable to display preview. Download preview PDF.
Similar content being viewed by others
References
ABBYY. ABBYY FineReader, http://finereader.abbyy.com
Chaudhari, S.K., Deshpande, A.R., Bendale, S.B., Kotian, R.V.: 3D Drag-n-drop CAPTCHA Enhanced Security through CAPTCHA. In: Mishra, B.K. (ed.) ICWET, pp. 598–601. ACM (2011)
Chellapilla, K., Larson, K., Simard, P.Y., Czerwinski, M.: Designing Human Friendly Human Interaction Proofs (HIPs). In: van der Veer, G.C., Gale, C. (eds.) CHI, pp. 711–720. ACM (2005)
Chellapilla, K., Simard, P.Y.: Using Machine Learning to Break Visual Human Interaction Proofs (HIPs). In: NIPS (2004)
Chow, Y.-W., Susilo, W., Zhou, H.-Y.: CAPTCHA Challenges for Massively Multiplayer Online Games: Mini-game CAPTCHAs. In: Proceedings of the 2010 International Conference on Cyberworlds, CW 2010, pp. 254–261. IEEE Computer Society, Washington, DC (2010)
Imsamai, M., Phimoltares, S.: 3D CAPTCHA: A Next Generation of the CAPTCHA. In: Proceedings of the International Conference on Information Science and Applications (ICISA 2010), Seoul, South Korea, April 21-23, pp. 1–8. IEEE Computer Society (2010)
Ince, I.F., Salman, Y.B., Yildirim, M.E., Yang, T.-C.: Execution Time Prediction for 3D Interactive CAPTCHA by Keystroke Level Model. In: Proceedings of the 2009 Fourth International Conference on Computer Sciences and Convergence Information Technology, ICCIT 2009, pp. 1057–1061. IEEE Computer Society, Washington, DC (2009)
Kolupaev, A., Ogijenko, J.: CAPTCHAs: Humans vs. Bots. IEEE Security & Privacy 6(1), 68–70 (2008)
Li, S., Shah, S.A.H., Khan, M.A.U., Khayam, S.A., Sadeghi, A.-R., Schmitz, R.: Breaking e-Banking CAPTCHAs. In: Gates, C., Franz, M., McDermott, J.P. (eds.) ACSAC, pp. 171–180. ACM (2010)
Macias, C., Izquierdo, E.: Visual Word-based CAPTCHA using 3D Characters. IET Seminar Digests 2009(2), P41–P41 (2009)
Mancas-Thillou, C., Ferreira, S., Demeyer, J., Minetti, C., Gosselin, B.: A Multifunctional Reading Assistant for the Visually Impaired. J. Image Video Process. 2007, 5:1–5:11 (2007)
Mori, G., Malik, J.: Recognizing Objects in Adversarial Clutter: Breaking a Visual CAPTCHA. In: CVPR (1), pp. 134–144 (2003)
Moy, G., Jones, N., Harkless, C., Potter, R.: Distortion Estimation Techniques in Solving Visual CAPTCHAs. In: CVPR (2), pp. 23–28 (2004)
OCR Research Team. Teabag 3D CAPTCHA, http://ocr-research.org.ua
Rediff Inc. Rediffmail, http://register.rediff.com/register/register.php
Ross, S.A., Halderman, J.A., Finkelstein, A.: Sketcha: a CAPTCHA based on Line Drawings of 3D Models. In: Rappa, M., Jones, P., Freire, J., Chakrabarti, S. (eds.) WWW, pp. 821–830. ACM (2010)
Susilo, W., Chow, Y.-W., Zhou, H.-Y.: STE3D-CAP: Stereoscopic 3D CAPTCHA. In: Heng, S.-H., Wright, R.N., Goi, B.-M. (eds.) CANS 2010. LNCS, vol. 6467, pp. 221–240. Springer, Heidelberg (2010)
von Ahn, L., Blum, M., Hopper, N.J., Langford, J.: CAPTCHA: Using Hard AI Problems for Security. In: Biham, E. (ed.) EUROCRYPT 2003. LNCS, vol. 2656, pp. 294–311. Springer, Heidelberg (2003)
Yan, J., Ahmad, A.S.E.: Breaking Visual CAPTCHAs with Naive Pattern Recognition Algorithms. In: ACSAC, pp. 279–291. IEEE Computer Society (2007)
Yan, J., Ahmad, A.S.E.: A Low-Cost Attack on a Microsoft CAPTCHA. In: ACM Conference on Computer and Communications Security, pp. 543–554 (2008)
Yan, J., Ahmad, A.S.E.: Usability of CAPTCHAs or Usability Issues in CAPTCHA Design. In: Cranor, L.F. (ed.) SOUPS. ACM International Conference Proceeding Series, pp. 44–52. ACM (2008)
Author information
Authors and Affiliations
Editor information
Editors and Affiliations
Rights and permissions
Copyright information
© 2012 Springer-Verlag Berlin Heidelberg
About this paper
Cite this paper
Nguyen, V.D., Chow, YW., Susilo, W. (2012). Breaking a 3D-Based CAPTCHA Scheme. In: Kim, H. (eds) Information Security and Cryptology - ICISC 2011. ICISC 2011. Lecture Notes in Computer Science, vol 7259. Springer, Berlin, Heidelberg. https://doi.org/10.1007/978-3-642-31912-9_26
Download citation
DOI: https://doi.org/10.1007/978-3-642-31912-9_26
Publisher Name: Springer, Berlin, Heidelberg
Print ISBN: 978-3-642-31911-2
Online ISBN: 978-3-642-31912-9
eBook Packages: Computer ScienceComputer Science (R0)