Tick Tock Break the Clock: Breaking CAPTCHAs on the Darkweb

David Audran, Marcus Andersen, Mark Hansen, Mikkel Andersen, Thomas Frederiksen, Kasper Hansen, Dimitrios Georgoulias, Emmanouil Vasilomanolakis

2022

Abstract

Nowadays, almost all major websites employ CAPTCHAs. This prevents website scraping, fake account creation as well as DDoS or bruteforce attacks. For anonymity reasons, mainstream CAPTCHAs such as Google’s reCAPTCHA cannot be used on the darkweb. Due to the evolution of machine learning and computer vision, the CAPTCHA challenges used there, such as the clock CAPTCHA, are usually more arduous than those found on the clearweb. This paper presents an automated system that uses machine learning to break clock CAPTCHA challenges with a high success rate. We evaluate our system in a real world setting against 725 clock challenges from live darkweb marketplaces. Our results show an accuracy of 96.83% while maintaining low time requirements while analyzing, predicting and submitting the CAPTCHA solution.

Download


Paper Citation


in Harvard Style

Audran D., Andersen M., Hansen M., Andersen M., Frederiksen T., Hansen K., Georgoulias D. and Vasilomanolakis E. (2022). Tick Tock Break the Clock: Breaking CAPTCHAs on the Darkweb. In Proceedings of the 19th International Conference on Security and Cryptography - Volume 1: SECRYPT, ISBN 978-989-758-590-6, pages 357-365. DOI: 10.5220/0011273300003283


in Bibtex Style

@conference{secrypt22,
author={David Audran and Marcus Andersen and Mark Hansen and Mikkel Andersen and Thomas Frederiksen and Kasper Hansen and Dimitrios Georgoulias and Emmanouil Vasilomanolakis},
title={Tick Tock Break the Clock: Breaking CAPTCHAs on the Darkweb},
booktitle={Proceedings of the 19th International Conference on Security and Cryptography - Volume 1: SECRYPT,},
year={2022},
pages={357-365},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0011273300003283},
isbn={978-989-758-590-6},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 19th International Conference on Security and Cryptography - Volume 1: SECRYPT,
TI - Tick Tock Break the Clock: Breaking CAPTCHAs on the Darkweb
SN - 978-989-758-590-6
AU - Audran D.
AU - Andersen M.
AU - Hansen M.
AU - Andersen M.
AU - Frederiksen T.
AU - Hansen K.
AU - Georgoulias D.
AU - Vasilomanolakis E.
PY - 2022
SP - 357
EP - 365
DO - 10.5220/0011273300003283