This suggests that their attack works in a fundamental level. Their attack appears to be applicable to a whole family of text CAPTCHAs that build on top of the popular segmentation resistant mechanism of "crowding character together" for security. They also proposed a novel framework that guides the application of their well-tested security engineering methodology for evaluating CAPTCHA robustness, and proposed a new general principle for CAPTCHA design.
They concluded that CAPTCHAs are still a new research area. Open problems include the mislabeling problem. Of all the problems they discussed, mislabeling causes the most human errors. The authors may be able to solve this using collaborative filtering, where known human users rate images according to how well they evoke their label. They presented more images per round in the anomaly detection CAPTCHA to debate computer performance.
A lot of work has been done in Enhancing CAPTCHA usability and Security one such example is use of re CAPTCHA[2], However emergence of recent advents and techniques made it more difficult to prevent automated bots and other dangerous spammers against CAPTCHA attacks. some techniques we have discussed in this paper provide more than 40% success rate, and as the faulty CAPTCHA requests are re-evaluated by the server and absence limiting count means that CAPTCHA decryption will be successful in consecutive attacks. In future we would like to use open source OCR Engines to validate such claims.
1. Luis Von An, Manuel Blum, Nicholas J. Hopper, and John Langford. 2003. CAPTCHA: using hard AI problems for security. In Proceedings of the 22nd international conference on Theory and applications of cryptographic techniques (EUROCRYPT'03), Eli Biham (Ed.). Springer-Overflag, Berlin, Heidelberg, 294-311.
2. Luis von An, Ben Maurer, Colin McMillan, David Abraham and Manuel Blum (2008). Re CAPTCHA: Human-Based Character Recognition via Web Security Measures. Science 321 (5895): 1465–1468.
3. Marti Motoyama, Krill Levchenko, Chris Kanich, Damon McCoy, Geoffrey M. Volker, and Stefan Savage. 2010. Re: CAPTCHAs: understanding CAPTCHA-solving services in an economic context. In Proceedings of the 19th USENIX conference on Security (USENIX Security'10). USENIX Association, Berkeley, CA, USA, 28-28.
4. Elie Bursztein, Steven Bet hard, Celine Fabry, John C. Mitchell, and Dan Jurafsky. 2010. How Good Are Humans at Solving CAPTCHAs? A Large Scale Evaluation. In Proceedings of the 2010 IEEE
Symposium on Security and Privacy (SP '10). IEEE Computer Society, Washington, DC, USA, 399-413.
5. Elie Bursztein, Mathieu Martin, and John Mitchell. 2011. Text-based CAPTCHA strengths and weaknesses. In Proceedings of the 18th ACM conference on Computer and communications security (CCS '11). ACM, New York, NY, USA
6. Ahmad Salah El Ahmad, Jeff Yan, and Lindsay Marshall. 2010. The robustness of a new CAPTCHA. In Proceedings of the Third European Workshop on System Security (EUROSEC '10). ACM, New York, NY, USA.
7. Bin B. Zhu, “Attacks and Design of Image Recognition CAPTCHAs”, ACM, Microsoft Research, Temple University, Computer and Information Science, OCT 2010.
8. Marti Motoyama, Krill et al. Re: CAPTCHAs: understanding CAPT-CHA solving services in an economic context. In Proceedings of the 19th USENIX conference on Security 28-28. v. 2010.