Gotta CAPTCHA 'Em All: A Survey of Twenty years of the Human-or-Computer Dilemma

03/02/2021
by   Meriem Guerar, et al.
0

A recent study has found that malicious bots generated nearly a quarter of overall website traffic in 2019 [100]. These malicious bots perform activities such as price and content scraping, account creation and takeover, credit card fraud, denial of service, etc. Thus, they represent a serious threat to all businesses in general, but are especially troublesome for e-commerce, travel and financial services. One of the most common defense mechanisms against bots abusing online services is the introduction of Completely Automated Public Turing test to tell Computers and Humans Apart (CAPTCHA), so it is extremely important to understand which CAPTCHA schemes have been designed and their actual effectiveness against the ever-evolving bots. To this end, this work provides an overview of the current state-of-the-art in the field of CAPTCHA schemes and defines a new classification that includes all the emerging schemes. In addition, for each identified CAPTCHA category, the most successful attack methods are summarized by also describing how CAPTCHA schemes evolved to resist bot attacks, and discussing the limitations of different CAPTCHA schemes from the security, usability and compatibility point of view. Finally, an assessment of the open issues, challenges, and opportunities for further study is provided, paving the road toward the design of the next-generation secure and user-friendly CAPTCHA schemes.

READ FULL TEXT

page 5

page 7

page 8

page 9

page 17

page 21

page 22

research
07/16/2023

CAPTCHA Types and Breaking Techniques: Design Issues, Challenges, and Future Research Directions

The proliferation of the Internet and mobile devices has resulted in mal...
research
06/13/2023

How Secure is Your Website? A Comprehensive Investigation on CAPTCHA Providers and Solving Services

Completely Automated Public Turing Test To Tell Computers and Humans Apa...
research
09/16/2019

DDoS Hide Seek: On the Effectiveness of a Booter Services Takedown

Booter services continue to provide popular DDoS-as-a-service platforms ...
research
04/09/2020

Efficient and Secure Flash-based Gaming CAPTCH

With the growth of connectivity to smart grids, new applications, and th...
research
02/04/2014

User Friendly Line CAPTCHAs

CAPTCHAs or reverse Turing tests are real-time assessments used by progr...
research
08/24/2020

Who ya gonna call? (Alerting Authorities): Measuring Namespaces, Web Certificates, and DNSSEC

During disasters, crisis, and emergencies the public relies on online se...
research
09/13/2022

An Extensive Study of Residential Proxies in China

We carry out the first in-depth characterization of residential proxies ...

Please sign up or login with your details

Forgot password? Click here to reset