Countering Automated Exploits with System Security CAPTCHAS
Many users routinely log in to their system with system administrator privileges. This is especially true of home users. The advantage of this setup is that these users can do everything necessary to fulfil their tasks with the computer. The disadvantage is that every program running in the users context can make arbitrary modifications to the system. Malicious programs and scripts often take advantage of this and silently change important parameters. We propose to verify that these changes were initiated by a human by a ceremony making use of a CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart). We compare this approach with other methods of achieving the same goal, i.e. passwords, secure path and access control based on zone of origin of the code.
KeywordsAccess Control User Context Turing Test Leaky Bucket Secure Storage
Unable to display preview. Download preview PDF.
- 1.Ellison, C.: UPnP Security Ceremonies Design Document (October 2003), www.upnp.org/download/standardizeddcps/UPnPSecurityCeremonies_1_0secure.pdf
- 4.Ahn, L., von Blum, M., Hopper, N.J., Langford, J.: The CAPTCHA Web page, http://www.captcha.net
- 5.Rissanen, E., Firozabadi, B.S., Sergot, M.: Towards A Mechanism for Discretionary Overriding of Access Control. In: World Computer Congress (2004)Google Scholar
- 6.Wang, Y.-M., Roussev, R., Verbowski, C., Johnson, A., Wu, M.-W., Huang, Y., Kuo, S.-Y.: Gatekeeper: Monitoring Auto-Start Extensibility Points (ASEPs) for Spyware Management. In: Proc. Usenix LISA (November 2004)Google Scholar
- 7.Microsoft Corporation. 10 Immutable Laws of Security. Technet, www.microsoft.com/technet/archive/community/columns/security/essays/10imlaws.mspx