Impeding CAPTCHA breakers with visual decryption

Simon R. Lang, Neville Williams · 2010

Abuse of free Internet resources and services from false account creation, to spam, to identity theft, ex-cessive bandwidth usage, or even vote stuffing online polls is a big problem. The Completely Automatic Public Turing Test to tell Computers and Humans Apart (CAPTCHA) controls access to resources but automated systems are increasingly adept at over-coming them. In this paper a method of access con-trol is introduced as an extra layer of security on top of existing CAPTCHA implementations. It uses visual encryption to encrypt images, which are pre-sented to clients like a CAPTCHA. It’s purpose is to compress many sub-images into a small image format that humans can decode visually but is hard for auto-mated systems due to decrypting overhead, and hav-ing to process more images to find the hidden image. This paper introduces visual encryption as a viable method to encrypt CAPTCHAs, and tests a proto-type to measure how efficiently users can find them. It also measures whether this method could impede a real CAPTCHA breaker. Results show humans de-tect images within 16-33 seconds, and deciphering images is almost 100%. Estimates on CAPTCHA breaking benchmarks show automated systems would be slowed significantly, even assuming the image is found and decoded. As sub-images increase, humans can process the visually encrypted images faster than automated systems can.

Read the paper · More papers on PaperTik