Skip to main navigation Skip to search Skip to main content

Analyzing DoS Attack Using Middlebox Amplification on CAPTCHA Server

  • University of Korea

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Denial-of-Service (DoS) attacks remain a significant threat to the Internet infrastructure, particularly when attackers leverage reflection and amplification techniques to generate largescale traffic with minimal resources. CAPTCHA servers, which are widely deployed to prevent automated access to web services, can inadvertently act as amplification vectors due to their automated and often large responses. In this paper, we investigate and analyze the potential security threat of reflected amplification DoS attacks utilizing CAPTCHA servers as middleboxes. Specifically, we focus on the structural characteristics of CAPTCHA servers that can be exploited to generate amplified traffic. Our methodology involves crafting and sending both normal and manipulated HTTP requests to an open-source CAPTCHA server, and measuring the corresponding amplification factors. The experimental results show that manipulated requests can achieve amplification factors up to 47.7x, significantly higher than those of standard interactions, thereby confirming the feasibility of abuse. For future work, we plan to extend our analysis to commercial CAPTCHA services and explore real-world attack feasibility in network environments that allow IP spoofing, as well as alternative TCP-layer bypass techniques.

Original languageEnglish
Title of host publicationICUFN 2025 - 16th International Conference on Ubiquitous and Future Networks
PublisherIEEE Computer Society
Pages78-80
Number of pages3
ISBN (Electronic)9798331524876
DOIs
StatePublished - 2025
Event16th International Conference on Ubiquitous and Future Networks, ICUFN 2025 - Hybrid, Lisbon, Portugal
Duration: 8 Jul 202511 Jul 2025

Publication series

NameInternational Conference on Ubiquitous and Future Networks, ICUFN
ISSN (Print)2165-8528
ISSN (Electronic)2165-8536

Conference

Conference16th International Conference on Ubiquitous and Future Networks, ICUFN 2025
Country/TerritoryPortugal
CityHybrid, Lisbon
Period8/07/2511/07/25

Keywords

  • CAPTCHA
  • DoS
  • Middlebox
  • Reflected Amplification attack

Fingerprint

Dive into the research topics of 'Analyzing DoS Attack Using Middlebox Amplification on CAPTCHA Server'. Together they form a unique fingerprint.

Cite this