Advertisement
Promo

Security management Toolkit

Google researcher presents video Captcha

Tom Espiner ZDNet.co.uk

Published: 13 Jul 2009 16:03 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new technique for using video to gauge whether a website is being accessed by a human or a machine will be presented at a Google-hosted security symposium this week.

The 'Completely Automated Public Turing test to tell Computers and Humans Apart' (Captcha) is designed to prevent abuse of websites, and normally involves users being presented with obscured text that they must recognise and enter into a dialogue box.

However, this type of Captcha can discourage people from using a website, according to Google researcher Kurt Alfred Kluever, and Rochester Institute of Technology assistant professor Richard Zanibbi. Respondents in two user studies preferred video, the researchers wrote in a paper entitled Balancing Usability and Security in a Video Captcha.

"A majority of participants (60 percent) indicated that they found the video Captchas more enjoyable than traditional Captchas in which distorted text must be transcribed," wrote Kluever and Zanibbi. The combined studies had 327 participants.

The technology uses images from YouTube videos as a starting point for the authentication test. Users are presented with a video clip, and type words into a dialogue box that they associate with that clip. Word association is graded depending on how similar the responses are to the tags on the videos, and to tags on other YouTube videos.

The researchers said they were able to tweak their algorithms to gain a human success rate on video Captcha of around 90 percent, with a simulated-attack success rate of approximately 13 percent.

When they tweaked their challenge-generation algorithm further, they reduced the attack success rate to two percent, with a human success rate of roughly 70 percent.

The researchers simulated the frequency-based attack by automatically submitting tags that labelled the largest set of videos, while taking into account security measures they had built into the technology. These security measures prune the tags linked to the YouTube videos, to lower the number in the set of common tags that are accepted for use by the video Captcha.

MessageLabs warned of an increase in Captcha-breaking spam in May. Breaking Captchas allows malware authors and spammers to use websites to propagate spam.

Kluever and Zanibbi will present their paper on Friday at the Symposium On Usable Privacy and Security (Soups 09) conference in Mountain View.

Video Captcha
 
An example of Kluever and Zanibbi's video Captcha
 

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

Post a comment

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters