Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Duc C. Hoang

dblp:353/2024 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2024
0000-0002-7416-6092ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Authentication and access control · 56% Web and mobile security · 44%

Topics — the 3 heaviest of 3, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control › human interactive proofs › CAPTCHA
CAPTCHA security
0.812024
The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern Web · WWW 2024
Web and mobile security
web application security
0.812024
The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern Web · WWW 2024
Authentication and access control › human interactive proofs
CAPTCHA
0.212024
The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern Web · WWW 2024

Methods — techniques the papers use, named apart from their topics

pre-trained model · 0.8local optimization · 0.8
YearPublicationVenuePosition
2024 The Matter of Captchas: An Analysis of a Brittle Security Feature on the Modern Web
abstract
The web ecosystem is a fast-paced environment. In this dynamic landscape, new security features are offered one after another to enhance the security and robustness of web applications and the operations they handle. This paper focuses on a fragile but still in-use security feature, text-based CAPTCHAs, that had been wildly used by web applications in the past to protect against automated attacks such as credential stuffing and account hijacking. The paper first investigates what it takes to develop automated scanners that can solve previously unseen text-based CAPTCHAs. We evaluated the possibility of developing and integrating a pre-trained CAPTCHA solver in the automated web scanning process without using a significantly large training dataset. We also perform an analysis of the impact of such autonomous scanners on CAPTCHA-enabled websites. Our analysis shows that solvable text-based CAPTCHAs on login, contact, and comment pages of websites are not uncommon. In particular, we identified over 3,100 text-based CAPTCHA websites in critical sectors such as finance, government, and health with hundreds of thousands of users. We showed that a web scanner with a pre-trained solver could solve more than 20% of previously unseen CAPTCHAs in just one single attempt. This result is worrisome considering the substantial potential to autonomously run the operation across thousands of websites on a daily basis with minimal training. The findings suggest that the integration of autonomous scanning with pre-training and local optimization of models can significantly increase adversaries' asymmetric power to launch their attacks cheaper and faster.
Behzad Ousat, Esteban Schafir, Duc C. Hoang, Mohammad Ali Tofighi, Viet Cuong Nguyen, Sajjad Arshad, A. Selcuk Uluagac, Amin Kharraz
WWW3