{"title":"基于用户行为模型的自动验证码网站保护","authors":"H. Awla, Arsalan Rahman Mirza, S. Kareem","doi":"10.1109/IEC54822.2022.9807472","DOIUrl":null,"url":null,"abstract":"Abstract-CAPTCHA (Completely Automated Public Test to tell Computers and Humans Apart) currently is the standard security technology and has been used widely in applications on commercial websites. It is an automated method with human maintenance and intervention and it is used for protecting the websites from automated attackers. There exist different types of CAPTCHA, ranging from difficult/easy to complex/simple ones. The problem with current CAPTCHAs is most of them use one single layout and simple user interface to distinguish the human from the attacker. This mechanism will help the attacker to easily bypass by using an appropriate bot program. In this paper, the main objective is to make a survey regarding the available security technique and evaluate the existing ones according to a set of characteristics for defending against attackers. Upon the evaluation result, a new user behavioral model has been proposed based on the user activity. In the proposed method the user behavior is scored according to the characteristics needed by their web applications. Finally, the model is implemented by building a web application and validated using an experimental setup and achieved a score of 70.26 for the usability of the model and the proposed method compared with other CAPTCHA tests and with the experimental evaluations, the proposed method is easier to solve and more user-friendly.","PeriodicalId":265954,"journal":{"name":"2022 8th International Engineering Conference on Sustainable Technology and Development (IEC)","volume":"126 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-02-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":"{\"title\":\"An Automated CAPTCHA for Website Protection Based on User Behavioral Model\",\"authors\":\"H. Awla, Arsalan Rahman Mirza, S. Kareem\",\"doi\":\"10.1109/IEC54822.2022.9807472\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Abstract-CAPTCHA (Completely Automated Public Test to tell Computers and Humans Apart) currently is the standard security technology and has been used widely in applications on commercial websites. It is an automated method with human maintenance and intervention and it is used for protecting the websites from automated attackers. There exist different types of CAPTCHA, ranging from difficult/easy to complex/simple ones. The problem with current CAPTCHAs is most of them use one single layout and simple user interface to distinguish the human from the attacker. This mechanism will help the attacker to easily bypass by using an appropriate bot program. In this paper, the main objective is to make a survey regarding the available security technique and evaluate the existing ones according to a set of characteristics for defending against attackers. Upon the evaluation result, a new user behavioral model has been proposed based on the user activity. In the proposed method the user behavior is scored according to the characteristics needed by their web applications. Finally, the model is implemented by building a web application and validated using an experimental setup and achieved a score of 70.26 for the usability of the model and the proposed method compared with other CAPTCHA tests and with the experimental evaluations, the proposed method is easier to solve and more user-friendly.\",\"PeriodicalId\":265954,\"journal\":{\"name\":\"2022 8th International Engineering Conference on Sustainable Technology and Development (IEC)\",\"volume\":\"126 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2022-02-23\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"2\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2022 8th International Engineering Conference on Sustainable Technology and Development (IEC)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/IEC54822.2022.9807472\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 8th International Engineering Conference on Sustainable Technology and Development (IEC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IEC54822.2022.9807472","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
An Automated CAPTCHA for Website Protection Based on User Behavioral Model
Abstract-CAPTCHA (Completely Automated Public Test to tell Computers and Humans Apart) currently is the standard security technology and has been used widely in applications on commercial websites. It is an automated method with human maintenance and intervention and it is used for protecting the websites from automated attackers. There exist different types of CAPTCHA, ranging from difficult/easy to complex/simple ones. The problem with current CAPTCHAs is most of them use one single layout and simple user interface to distinguish the human from the attacker. This mechanism will help the attacker to easily bypass by using an appropriate bot program. In this paper, the main objective is to make a survey regarding the available security technique and evaluate the existing ones according to a set of characteristics for defending against attackers. Upon the evaluation result, a new user behavioral model has been proposed based on the user activity. In the proposed method the user behavior is scored according to the characteristics needed by their web applications. Finally, the model is implemented by building a web application and validated using an experimental setup and achieved a score of 70.26 for the usability of the model and the proposed method compared with other CAPTCHA tests and with the experimental evaluations, the proposed method is easier to solve and more user-friendly.