作者
Shujun Li, S Amier Haider Shah, M Asad Usman Khan, Syed Ali Khayam, Ahmad-Reza Sadeghi, Roland Schmitz
发表日期
2010/12/6
图书
Proceedings of the 26th Annual Computer Security Applications Conference
页码范围
171-180
简介
Many financial institutions have deployed CAPTCHAs to protect their services (e.g., e-banking) from automated attacks. In addition to CAPTCHAs for login, CAPTCHAs are also used to prevent malicious manipulation of e-banking transactions by automated Man-in-the-Middle (MitM) attackers. Despite serious financial risks, security of e-banking CAPTCHAs is largely unexplored. In this paper, we report the first comprehensive study on e-banking CAPTCHAs deployed around the world. A new set of image processing and pattern recognition techniques is proposed to break all e-banking CAPTCHA schemes that we found over the Internet, including three e-banking CAPTCHA schemes for transaction verification and 41 schemes for login. These broken e-banking CAPTCHA schemes are used by thousands of financial institutions worldwide, which are serving hundreds of millions of e-banking customers. The success …
引用总数
201120122013201420152016201720182019202020212022202320244871215988752131
学术搜索中的文章
S Li, SAH Shah, MAU Khan, SA Khayam, AR Sadeghi… - Proceedings of the 26th Annual Computer Security …, 2010