Analyzing DoS Attack Using Middlebox Amplification on CAPTCHA Server

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Denial-of-Service (DoS) attacks remain a significant threat to the Internet infrastructure, particularly when attackers leverage reflection and amplification techniques to generate largescale traffic with minimal resources. CAPTCHA servers, which are widely deployed to prevent automated access to web services, can inadvertently act as amplification vectors due to their automated and often large responses. In this paper, we investigate and analyze the potential security threat of reflected amplification DoS attacks utilizing CAPTCHA servers as middleboxes. Specifically, we focus on the structural characteristics of CAPTCHA servers that can be exploited to generate amplified traffic. Our methodology involves crafting and sending both normal and manipulated HTTP requests to an open-source CAPTCHA server, and measuring the corresponding amplification factors. The experimental results show that manipulated requests can achieve amplification factors up to 47.7x, significantly higher than those of standard interactions, thereby confirming the feasibility of abuse. For future work, we plan to extend our analysis to commercial CAPTCHA services and explore real-world attack feasibility in network environments that allow IP spoofing, as well as alternative TCP-layer bypass techniques.

Original languageEnglish
Title of host publicationICUFN 2025 - 16th International Conference on Ubiquitous and Future Networks
PublisherIEEE Computer Society
Pages78-80
Number of pages3
ISBN (Electronic)9798331524876
DOIs
Publication statusPublished - 2025
Externally publishedYes
Event16th International Conference on Ubiquitous and Future Networks, ICUFN 2025 - Hybrid, Lisbon, Portugal
Duration: 2025 Jul 82025 Jul 11

Publication series

NameInternational Conference on Ubiquitous and Future Networks, ICUFN
ISSN (Print)2165-8528
ISSN (Electronic)2165-8536

Conference

Conference16th International Conference on Ubiquitous and Future Networks, ICUFN 2025
Country/TerritoryPortugal
CityHybrid, Lisbon
Period25/7/825/7/11

Bibliographical note

Publisher Copyright:
© 2025 IEEE.

Keywords

  • CAPTCHA
  • DoS
  • Middlebox
  • Reflected Amplification attack

ASJC Scopus subject areas

  • Hardware and Architecture
  • Computer Science Applications
  • Computer Networks and Communications

Fingerprint

Dive into the research topics of 'Analyzing DoS Attack Using Middlebox Amplification on CAPTCHA Server'. Together they form a unique fingerprint.

Cite this