Blocking via an unsolvable captcha
Abstract
A security device may receive a request from an attacker device and intended for a server device. The security device may identify the request as being associated with a malicious activity. The malicious activity may include one or more undesirable tasks directed to the server device. The security device may generate an unsolvable challenge-response test based on identifying the request as being associated with the malicious activity. The unsolvable challenge-response test may be generated using at least one construction technique and may be configured in an attempt to block the attacker device without making the attacker device aware that the attacker device is being blocked. The security device may provide the unsolvable challenge-response test to the attacker device, and may receive a solution associated with the unsolvable challenge-response test. The security device may notify the attacker device that the solution is incorrect regardless of whether the solution is actually correct.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A system comprising:
one or more processors to:
identify an attacker device;
select, based on identifying the attacker device, a construction technique associated with displaying an error;
generate an unsolvable challenge-response test using the construction technique,
the unsolvable challenge-response test including information for causing the attacker device to display the error without making the attacker device aware that the attacker device is being blocked; and
provide the unsolvable challenge-response test to the attacker device.
22 . The system of claim 21 ,
where the one or more processors are further to:
obtain information indicating multiple failed attempts to log into a user account from a particular device, and
where the one or more processors, when identifying the attacker device, are to:
identify that the particular device is the attacker device based on the multiple failed attempts from the particular device.
23 . The system of claim 21 ,
where the one or more processors are further to:
receive a request from the attacker device; and
determine that the request is associated with malicious activity, and
where the one or more processors, when identifying the attacker device, are further to:
identify the attacker device based on determining that the request is associated with malicious activity.
24 . The system of claim 21 , where the unsolvable challenge-response test comprises an unsolvable completely automated public Turing test to tell Computers and Humans Apart (CAPTCHA).
25 . The system of claim 21 , where the one or more processors are further to:
provide an initial challenge-response test to the attacker device before providing the unsolvable challenge-response test to the attacker device.
26 . The system of claim 25 , where one or more processors are further to:
generate the initial challenge-response test by distorting a character included in the unsolvable challenge-response test.
27 . The system of claim 25 , where the initial challenge-response test requires the attacker device to submit a solution to the initial challenge-response test without a user of the attacker device being able to view the initial challenge-response test for a time necessary to submit the solution.
28 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
one or more instructions that, when executed by one or more processors, cause the one or more processors to:
identify an attacker device;
select, based on identifying the attacker device, a construction technique;
generate an unsolvable challenge-response test using the construction technique,
the unsolvable challenge-response test including information for causing the attacker device to prompt a user of the attacker device without making the attacker device aware that the attacker device is being blocked; and
provide the unsolvable challenge-response test to the attacker device.
29 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions to identify the attacker device comprise:
one or more instructions that, when executed by the one or more processors, cause the one or more processors to:
identify the attacker device based on information indicating multiple failed attempts from the attacker device.
30 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions to identify the attacker device comprise:
one or more instructions that, when executed by the one or more processors, cause the one or more processors to:
identify the attacker device based on a request, from the attacker device, associated with malicious activity.
31 . The non-transitory computer-readable medium of claim 28 , where a correct solution, to the unsolvable challenge-response test, comprises a character that a user of the attacker device cannot input.
32 . The non-transitory computer-readable medium of claim 28 ,
where the unsolvable challenge-response test comprises an unsolvable completely automated public Turing test to tell Computers and Humans Apart (CAPTCHA), and where the unsolvable CAPTCHA comprises a character that appears similar to another character.
33 . The non-transitory computer-readable medium of claim 28 ,
where the unsolvable challenge-response test comprises an unsolvable completely automated public Turing test to tell Computers and Humans Apart (CAPTCHA), where the unsolvable CAPTCHA comprises a first quantity of characters to be displayed, and where the unsolvable CAPTCHA requires a solution that includes a second quantity of characters that is different from the first quantity of characters.
34 . The non-transitory computer-readable medium of claim 28 , where the unsolvable challenge-response test includes an error, to be displayed by the attacker device, that indicates that the attacker device is unable to display an image.
35 . A method comprising:
identifying, by a device, an attacker device; generating, by the device, a unsolvable challenge-response test for the attacker device,
the unsolvable challenge-response test including information for causing the attacker device to display a user interface without making the attacker device aware that the attacker device is being blocked; and
providing, by the device, the unsolvable challenge-response test to the attacker device.
36 . The method of claim 35 , further comprising:
selecting, based on identifying the attacker device, a construction technique associated with displaying an error,
where generating the unsolvable challenge-response test comprises:
generating the unsolvable challenge-response test using the construction technique.
37 . The method of claim 36 ,
where the user interface includes the error, and where the error indicates that the attacker device is unable to display an image.
38 . The method of claim 35 , where the user interface includes an input field that does not allow the attacker device to input a solution into the input field.
39 . The method of claim 35 , where the user interface includes information indicating that the unsolvable challenge-response test could not be generated.
40 . The method of claim 35 , further comprising:
notifying the attacker device that a first solution to the unsolvable challenge-response test is incorrect; and permitting the attacker device to provide a second solution to the unsolvable challenge-response test.Join the waitlist — get patent alerts
Track US2016330240A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.