C-Frame

Characterizing and measuring in-the-wild CAPTCHA attacks

Obscured by complexity IEEE S&P 2024 Web Paper

CAPTCHAs are meant to separate humans from bots. CAPTCHA-bypass-for-hire services defeat them by routing each challenge to human workers in a solving farm. Because every farm serves many customers, looking at any single targeted website shows only a sliver of the activity. Earlier work had studied the ecosystem only site by site.

Measuring from the inside

C-Frame extends our interaction-driven measurement approach from PhishInPatterns to this ecosystem. It observes the CAPTCHA tasks that solving farms hand to their workers, recording which websites the tasks target before they reach the CAPTCHA service.

C-Frame design: observing tasks between CAPTCHA farms and their workers
C-Frame observes CAPTCHA tasks as they flow from solving farms to workers, and records the targeted sites.

Key contributions

  • The first cross-organization view of CAPTCHA attacks, measured from inside solving farms.
  • A characterization of which websites and CAPTCHA services these farms target in the wild.

Citation. Hoang Dai Nguyen, Karthika Subramani, Bhupendra Acharya, Roberto Perdisci, Phani Vadrevu. C-Frame: Characterizing and Measuring In-the-Wild CAPTCHA Attacks. IEEE Symposium on Security and Privacy (S&P), 2024.