IMPORTANT DATES
February 1, 2017 Abstract and optional full paper submission begins
May 26, 2017 Exhibit & Supporter registration opens
June 15, 2017 Abstract and optional extended abstract submission ends
June 29, 2017 Acceptance notifications sent
July 24, 2017 Submit final abstracts and presenter biographies
August 28, 2017 Submit final presentations and optional full papers

Abstract Details

<< Back to Schedule

9/27/2017  |   1:05 PM - 1:50 PM   |  

A Unicode Based CAPTCHA Scheme

The presentation will discuss a highly flexible visual CAPTCHA scheme that leverages the 64K Unicode code points from the Basic Multilingual Plane (plane 0) to construct the CAPTCHAs that can be solved with 2 to 4 mouse clicks. We will review the challenges faced via designing the CAPTCHA system, its design principles, the different security mechanisms implemented into the CAPTCHA, and its various features that allow the CAPTCHA to be configured for different device types, including mobile and desktop. There will be several demonstrations around different modes and configurations of its operation. We will discuss the pros and cons of the different configurations and the possible security implications. The attendees will also get to experiment with the CAPTCHA during or after the conference on a publicly hosted website, or on a desktop based Swing application, and explore its Java source code via a public github repo. We will also discuss the potential attack vectors on the proposed CAPTCHA scheme. Source code: https://github.com/salesforce/pixel-captcha-project Important: This paper was published in CrossTalk magazine

Presentation:
This presentation has not yet been uploaded.

Handouts:
No handouts have been uploaded.

Gursev Singh Kalra (Primary Presenter,Author), Salesforce.com, gursev.kalra@gmail.com;
Gursev Singh Kalra is a Product Security Director at Salesforce.com where he works with several product teams to build secure software. He worked with McAfee as a Senior Principal Consultant and led multiple software security service lines. He has authored free security tools like PixelCAPTCHA, JMSDigger, TesserCap, Oyedata, SSLSmart etc… He has written several security related whitepapers and his research has been voted among the top ten web hacking techniques of 2011 and 2012. He has spoken at conferences like BlackHat, OWASP AppSec, NullCon, Focus, ToorCon, and Infosec Southwest etc.

2017 Sponsors: IEEE and IEEE Computer Society