Tick Tock Break the Clock: Breaking CAPTCHAs on the Darkweb

David Audran, Marcus Andersen, Mark Hansen, Mikkel Andersen, Thomas Frederiksen, Kasper Hansen, Dimitrios Georgoulias, Emmanouil Vasilomanolakis

Research output: Contribution to book/anthology/report/conference proceedingArticle in proceedingResearchpeer-review

1 Citation (Scopus)
46 Downloads (Pure)

Abstract

Nowadays, almost all major websites employ CAPTCHAs. This prevents website scraping, fake account creation as well as DDoS or bruteforce attacks. For anonymity reasons, mainstream CAPTCHAs such as Google’s reCAPTCHA cannot be used on the darkweb. Due to the evolution of machine learning and computer vision, the CAPTCHA challenges used there, such as the clock CAPTCHA, are usually more arduous than those found on the clearweb. This paper presents an automated system that uses machine learning to break clock CAPTCHA challenges with a high success rate. We evaluate our system in a real world setting against 725 clock challenges from live darkweb marketplaces. Our results show an accuracy of 96.83% while maintaining low time requirements while analyzing, predicting and submitting the CAPTCHA solution.
Original languageEnglish
Title of host publicationProceedings of the 19th International Conference on Security and Cryptography
EditorsSabrina De Capitani di Vimercati , Pierangela Samarati
Volume1
PublisherSCITEPRESS Digital Library
Publication date2022
Pages357-365
ISBN (Electronic)978-989-758-590-6
DOIs
Publication statusPublished - 2022
Event19th International Conference on Security and Cryptography (SECRYPT 2022) - Lisbon, Portugal
Duration: 11 Jul 202213 Jul 2022
Conference number: 19
https://secrypt.scitevents.org/

Conference

Conference19th International Conference on Security and Cryptography (SECRYPT 2022)
Number19
Country/TerritoryPortugal
CityLisbon
Period11/07/202213/07/2022
Internet address
SeriesInternational Conference on Security and Cryptography - SECRYPT - Proceedings
ISSN2184-7711

Fingerprint

Dive into the research topics of 'Tick Tock Break the Clock: Breaking CAPTCHAs on the Darkweb'. Together they form a unique fingerprint.

Cite this