UNI-CAPTCHA: A Novel Robust and Dynamic User-Non-Interaction CAPTCHA Model Based on Hybrid biLSTM+Softmax. (December 2021)
- Record Type:
- Journal Article
- Title:
- UNI-CAPTCHA: A Novel Robust and Dynamic User-Non-Interaction CAPTCHA Model Based on Hybrid biLSTM+Softmax. (December 2021)
- Main Title:
- UNI-CAPTCHA: A Novel Robust and Dynamic User-Non-Interaction CAPTCHA Model Based on Hybrid biLSTM+Softmax
- Authors:
- Süzen, Ahmet Ali
- Abstract:
- Highlights: We propose a new robust CAPTCHA recognition model called UNI-CAPTCHA. A dataset consisting of behavioral user and bot data specific to the study was used. Development of a CAPTCHA engine based on hybrid bi-LSTM+Softmax, which provides high accuracy. Detection and Prevention of suspicious user behavior as opposed to user-bot detection only. Fast response time and front-end side operation non-user interaction. Abstract: The security of web applications is protected by firewalls, intrusion detection systems or deep learning-based approaches. Although existing systems perform rules and content-based filtering, they can be bypassed with payloads and advanced bots in different scenarios. CAPTCHA is preferred to prevent bots in web applications to minimize possible risks. Although captcha applications make bot-user distinction, it can be solved with software-based systems. In addition, increasing the difficulty level of CAPTCHA schemes have bringing usage difficulties. In this study, a robust behavior-based CAPTCHA (UNI-CAPTCHA) was developed that detects user-bot without interaction with user. A web application with a landing page, login page, and register page has been developed for UNI-CAPTCHA to learn user and bot behavior. The application was tested with 16 different vulnerability tool bots and real users, creating a unique dataset containing 13 different behaviors. A risk rating was made using the k-Means++ algorithm based on characteristics of user behavior inHighlights: We propose a new robust CAPTCHA recognition model called UNI-CAPTCHA. A dataset consisting of behavioral user and bot data specific to the study was used. Development of a CAPTCHA engine based on hybrid bi-LSTM+Softmax, which provides high accuracy. Detection and Prevention of suspicious user behavior as opposed to user-bot detection only. Fast response time and front-end side operation non-user interaction. Abstract: The security of web applications is protected by firewalls, intrusion detection systems or deep learning-based approaches. Although existing systems perform rules and content-based filtering, they can be bypassed with payloads and advanced bots in different scenarios. CAPTCHA is preferred to prevent bots in web applications to minimize possible risks. Although captcha applications make bot-user distinction, it can be solved with software-based systems. In addition, increasing the difficulty level of CAPTCHA schemes have bringing usage difficulties. In this study, a robust behavior-based CAPTCHA (UNI-CAPTCHA) was developed that detects user-bot without interaction with user. A web application with a landing page, login page, and register page has been developed for UNI-CAPTCHA to learn user and bot behavior. The application was tested with 16 different vulnerability tool bots and real users, creating a unique dataset containing 13 different behaviors. A risk rating was made using the k-Means++ algorithm based on characteristics of user behavior in the dataset. The trained hybrid bi-LSTM + Softmax based UNI-CAPTCHA engine intuitively performs user-bot labeling of requests from the web application simultaneously. It also determines the risk rating of user labels from 1 to 5. The threshold user value (ε t ) for high protection is determined in the evaluation, and results below ε t, its value is evaluated as bot behavior and prevented. In UNI-Captcha, the threshold value of suspicious user behavior is adjusted according to the in-app security risk level. Analysis shows that the UNI-CAPTCHA engine shows better stability, speed, and detection than traditional bot detection and CAPTCHA applications. … (more)
- Is Part Of:
- Journal of information security and applications. Volume 63(2022)
- Journal:
- Journal of information security and applications
- Issue:
- Volume 63(2022)
- Issue Display:
- Volume 63, Issue 2022 (2022)
- Year:
- 2022
- Volume:
- 63
- Issue:
- 2022
- Issue Sort Value:
- 2022-0063-2022-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-12
- Subjects:
- Anomaly Behavior Detection -- Bi-LSTM -- Bot Detection -- CAPTCHA -- Intrusion Detection
Computer security -- Periodicals
Information technology -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/ ↗
- DOI:
- 10.1016/j.jisa.2021.103036 ↗
- Languages:
- English
- ISSNs:
- 2214-2126
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 20158.xml