透過您的圖書館登入
IP:18.188.255.116
  • 學位論文

以拼字為基礎之點擊式驗證碼

A Spelling Based CAPTCHA System By Using Click

指導教授 : 黃國峰

摘要


驗證碼已被廣泛使用於防止惡意程式自動存取網路資源,本篇論文提出一個新的驗證碼架構,並將此驗證碼命名為「Clickspell」。Clickspell結合文字與圖像驗證碼的特徵,利用文字外觀提示概念、影像遮罩與按鈕點擊的方式,使用者可以更容易理解圖像內容與避免輸入時的錯誤率,增加一般使用者通過驗證碼測試的成功率並降低攻擊成功率。另外,Clickspell提供字典功能與圖像置入機制,故使用者可以藉由字典功能學習驗證碼單詞內容的定義與發音,亦可彈性選擇是否置入廣告圖像於Clickspell中。若將廣告圖像置入於Clickspell形成驗證碼遮罩,則Clickspell將更具防止惡意程式攻擊的能力。Clickspell的驗證碼測試係由系統資料庫隨機選取英文單詞內容並對各單詞字母進行影像處理後顯示,使用者必須正確的辨識,並依序且正確的點擊各單字字母按鈕方可通過驗證。根據測試結果指出,Clickspell在安全性以及使用性的評估上皆具實用性。

並列摘要


CAPTCHA has been widely used for preventing malicious programs to access web resources automatically. In this thesis, a new type CAPTCHA system is proposed. The proposed scheme, named Clickspell, combined the features of text-based and image-based CAPTCHAs. Clickspell asks users to spell a randomly chosen word by clicking distorted letters for passing the test. Users can understand the image content by font shapes and pass test by mouse click to avoid input errors. Clickspell can be added with an image mask to improve the security. Furthermore, Clickspell has two augmented functions. First, users can learn the definition(s) of the chosen word. Second, Clickspell can add an advertisement image optionally. Thanks to the advertisement image, Clickspell improved the capability of resistance to the attack by malicious programs. Our preliminary test showed that Clickspell is practical in the aspects of security and usability.

參考文獻


[2] A. O. Thomas, A. Rusu, and V. Govindaraju, “Synthetic handwritten captchas,” Pattern Recognition, vol. 42, pp. 3365–3373, December 2009.
[4] P. Matthews and C. C. Zou, “Scene tagging: image-based captcha using image composition and object relationships,” in Proceedings of the 5th ACM Symposium on Information, Computer and Communications Security, ASIACCS ’10,
[5] A. Basso and S. Sicco, “Preventing massive automated access to web resources,” Computers & Security, vol. 28, pp. 174–188, 2009.
[7] Y. Soupionis and D. Gritzalis, “Audio captcha: Existing solutions assessment and a new implementation for voip telephony,” Computers & Security, vol. 29, no. 5, pp. 603 – 618, 2010.
[8] R. Stevanovi´c, G. Topi´c, K. Skala, M. Stipˇcevi´c, B. M. Rogina, Largescale scientific computing, Springer-Verlag, Berlin, Heidelberg, 2008, Ch. Quantum Random Bit Generator Service for Monte Carlo and Other Stochastic Simulations, pp. 508–515.

延伸閱讀