{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,29]],"date-time":"2026-03-29T15:58:27Z","timestamp":1774799907928,"version":"3.50.1"},"reference-count":42,"publisher":"MDPI AG","issue":"3","license":[{"start":{"date-parts":[[2022,3,10]],"date-time":"2022-03-10T00:00:00Z","timestamp":1646870400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Future Internet"],"abstract":"<jats:p>Phishing is a cybercrime that is increasing exponentially day by day. In phishing, a phisher employs social engineering and technology to misdirect victims towards revealing their personal information, which can then be exploited. Despite ongoing research to find effective anti-phishing solutions, phishing remains a serious security problem for Internet users. In this paper, an investigation of using CAPTCHA keystroke dynamics to enhance the prevention of phishing attacks was presented. A controlled laboratory experiment was conducted, with the results indicating the proposed approach as highly effective in protecting online services from phishing attacks. The results showed a 0% false-positive rate and 17.8% false-negative rate. Overall, the proposed solution provided a practical and effective way of preventing phishing attacks.<\/jats:p>","DOI":"10.3390\/fi14030082","type":"journal-article","created":{"date-parts":[[2022,3,10]],"date-time":"2022-03-10T11:46:47Z","timestamp":1646912807000},"page":"82","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["Investigation of Using CAPTCHA Keystroke Dynamics to Enhance the Prevention of Phishing Attacks"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5640-6523","authenticated-orcid":false,"given":"Emtethal K.","family":"Alamri","sequence":"first","affiliation":[{"name":"Department of Information Technology, College of Computer, Qassim University, Buraydah 51452, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3223-1105","authenticated-orcid":false,"given":"Abdullah M.","family":"Alnajim","sequence":"additional","affiliation":[{"name":"Department of Information Technology, College of Computer, Qassim University, Buraydah 51452, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7735-9781","authenticated-orcid":false,"given":"Suliman A.","family":"Alsuhibany","sequence":"additional","affiliation":[{"name":"Department of Computer Science, College of Computer, Qassim University, Buraydah 51452, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,3,10]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"139","DOI":"10.1007\/s11235-020-00733-2","article-title":"A comprehensive survey of AI-enabled phishing attacks detection techniques","volume":"76","author":"Basit","year":"2021","journal-title":"Telecommun. Syst."},{"key":"ref_2","first-page":"390","article-title":"A survey on various cyber attacks and their classification","volume":"15","author":"Uma","year":"2013","journal-title":"Int. J. Netw. Secur."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1186\/s40163-014-0009-y","article-title":"Achieving a consensual definition of phishing based on a systematic review of the literature","volume":"3","author":"Lastdrager","year":"2014","journal-title":"Crime Sci."},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Jakobsson, M., and Myers, S. (2006). Phishing and Countermeasures: Understanding the Increasing Problem of Electronic Identity Thef, John Wiley & Sons.","DOI":"10.1002\/0470086106"},{"key":"ref_5","unstructured":"APWG (2022, February 23). Phishing Activity Trends Report: 3rd Quarter 2021. Available online: https:\/\/docs.apwg.org\/reports\/apwg_trends_report_q3_2021.pdf?_ga=2.147528119.149518382.1644108193-680326765.1644108193&_gl=1*cr9iea*_ga*NjgwMzI2NzY1LjE2NDQxMDgxOTM.*_ga_55RF0RHXSR*MTY0NDEwODE5My4xLjAuMTY0NDEwODE5My4w."},{"key":"ref_6","unstructured":"Hewage, C. (2020). Coronavirus pandemic has unleashed a wave of cyber attacks-here\u2019s how to protect yourself. Conversation, 31, Available online: https:\/\/theconversation.com\/coronavirus-pandemic-has-unleashed-a-wave-of-cyber-attacks-heres-how-to-protect-yourself-135057."},{"key":"ref_7","unstructured":"Federal Bureau of Investigation-Internet Crime Complaint Center (IC3) (2022, February 23). 2020 Internet Crime Report, Available online: https:\/\/www.ic3.gov\/Media\/PDF\/AnnualReport\/2020_IC3Report.pdf."},{"key":"ref_8","unstructured":"Kulikova, T., Shcherbakova, T., and Sidorina, T. (2022, February 23). Spam and phishing in Q1 2021. Available online: https:\/\/securelist.com\/spam-and-phishing-in-q1-2021\/102018\/."},{"key":"ref_9","unstructured":"Kulikova, T., Shcherbakova, T., and Sidorina, T. (2021). Spam and phishing in 2020. Secur. Kapersky, Available online: https:\/\/securelist.com\/spam-and-phishing-in-2020\/100512\/."},{"key":"ref_10","unstructured":"Ponemon, L. (2022, February 23). The 2021 Cost of Phishing Study. Available online: https:\/\/www.proofpoint.com\/us\/resources\/analyst-reports\/ponemon-cost-of-phishing-study."},{"key":"ref_11","unstructured":"Stanford University IT (2022, February 23). University IT Launches Phishing Awareness Service. Available online: https:\/\/uit.stanford.edu\/news\/university-it-launches-phishing-awareness-service."},{"key":"ref_12","first-page":"161","article-title":"Person identification based on keystroke dynamics: Demo and open challenge","volume":"1612","author":"Buza","year":"2016","journal-title":"CEUR Workshop Proc."},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Brodi\u0107, D., and Amelio, A. (2020). The CAPTCHA\u2014Perspectives and Challenges Perspectives and Challenges, Springer Nature.","DOI":"10.1007\/978-3-030-29345-1"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Ahn, L.V., Blum, M., Hopper, N.J., and Langford, J. (2003). CAPTCHA: Using Hard AI Problems for Security, Springer Nature. Lecture Notes in Computer Science.","DOI":"10.1007\/3-540-39200-9_18"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"6266","DOI":"10.1002\/sec.1674","article-title":"A survey and classification of web phishing detection schemes","volume":"9","author":"Varshney","year":"2016","journal-title":"Secur. Commun. Networks"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Masri, R., and Aldwairi, M. (2017, January 4\u20136). Automated Malicious Advertisement Detection using VirusTotal, URLVoid, and TrendMicro. Proceedings of the 2017 8th International Conference on Information and Communication Systems (ICICS), Irbid, Jordan.","DOI":"10.1109\/IACS.2017.7921994"},{"key":"ref_17","first-page":"1","article-title":"A novel approach to protect against phishing attacks at client side using auto-updated white-list","volume":"2016","author":"Jain","year":"2016","journal-title":"EURASIP J. Inf. Secur."},{"key":"ref_18","first-page":"687","article-title":"Towards detection of phishing websites on client-side using machine learning based approach","volume":"68","author":"Kumar","year":"2017","journal-title":"Telecommun. Syst."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Mao, J., Li, P., Li, K., Wei, T., and Liang, Z. (2013, January 9\u201311). BaitAlarm: Detecting phishing sites using similarity in fundamental visual features. Proceedings of the 2013 5th International Conference on Intelligent Networking and Collaborative Systems, Xi\u2019an, China.","DOI":"10.1109\/INCoS.2013.151"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Tirfe, D., and Anand, V.K. (2022). A survey on trends of two-factor authentication. Contemporary Issues in Communication, Cloud and Big Data Analytics, Springer.","DOI":"10.1007\/978-981-16-4244-9_23"},{"key":"ref_21","first-page":"7","article-title":"Preventing Phishing Attacks using One Time Password and User Machine Identification","volume":"68","author":"Khan","year":"2013","journal-title":"Int. J. Comput. Appl."},{"key":"ref_22","unstructured":"Lee, Y.S., Kim, N.H., Lim, H., Jo, H.K., and Lee, H.J. (December, January 30). Online Banking Authentication system using Mobile-OTP with QR-code. Proceedings of the 5th International Conference on Computer Sciences and Convergence Information Technology ICCIT 2010, Seoul, Korea."},{"key":"ref_23","first-page":"88","article-title":"Fingerprint authentication technique to prevent phishing using pattern matrix","volume":"6","author":"Patel","year":"2013","journal-title":"Int. J. Eng. Res. Dev."},{"key":"ref_24","unstructured":"Jepkemboi, C.L. (2018). Enhancing Security of Mpesa Transactions by Use of Voice Biometrics. [Ph.D. Thesis, United States International University-Africa]."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Hassan, M.A., and Shukur, Z. (2021, January 29\u201331). A secure multi factor user authentication framework for electronic payment system. Proceedings of the 2021 3rd International Cyber Resilience Conference (CRC) 2021, Langkawi Island, Malaysia.","DOI":"10.1109\/CRC50527.2021.9392564"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"James, D., and Philip, M. (2012, January 3\u20136). A novel anti phishing framework based on visual cryptography. Proceedings of the 2012 International Conference on Power, Signals, Controls and Computation, Thrissur, India.","DOI":"10.1109\/EPSCICON.2012.6175228"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"5934","DOI":"10.1002\/sec.1747","article-title":"A novel method to authenticate in website using CAPTCHA-based validation","volume":"9","author":"Krishnamoorthy","year":"2016","journal-title":"Secur. Commun. Netw."},{"key":"ref_28","unstructured":"Nanglae, N., and Bhattarakosol, P. (June, January 30). A study of human bio-detection function under text-based CAPTCHA system. Proceedings of the 11th IEEE\/ACIS International Conference on Computer and Information Science, Shanghai, China."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"8","DOI":"10.1016\/S0969-4765(16)30035-2","article-title":"The growing pain of phishing: Is biometrics the cure?","volume":"2016","author":"Costigan","year":"2016","journal-title":"Biom. Technol. Today"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"1565","DOI":"10.1016\/j.asoc.2010.08.003","article-title":"Biometric personal authentication using keystroke dynamics: A review","volume":"11","author":"Karnan","year":"2011","journal-title":"Appl. Soft Comput. J."},{"key":"ref_31","doi-asserted-by":"crossref","unstructured":"Alsultan, A., and Warwick, K. (2013, January 13\u201316). User-friendly free-text keystroke dynamics authentication for practical applications. Proceedings of the 2013 IEEE International Conference on Systems, Man, and Cybernetics, SMC 2013, Washington, DC, USA.","DOI":"10.1109\/SMC.2013.793"},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"164","DOI":"10.1049\/iet-bmt.2015.0101","article-title":"Free-text keystroke dynamics authentication for Arabic language","volume":"5","author":"Alsultan","year":"2016","journal-title":"IET Biom."},{"key":"ref_33","doi-asserted-by":"crossref","unstructured":"Alsuhibany, S.A., Almushyti, M., Alghasham, N., and Alkhudier, F. (2016, January 28\u201330). Analysis of free-Text keystroke dynamics for Arabic language using Euclidean distance. Proceedings of the 2016 12th International Conference on Innovations in Information Technology, IIT 2016, Al-Ain, United Arab Emirates.","DOI":"10.1109\/INNOVATIONS.2016.7880049"},{"key":"ref_34","unstructured":"Garrett, P.B. (2014). Linear algebra I: Dimension. Number Theory, Trace Formulas and Discrete Groups, Academic Press."},{"key":"ref_35","unstructured":"Rouaud, M. (2022, February 23). Probability, Statistics and Estimation: Propagation of Uncertainties, p.191. 865 Creative Commons. Available online: http:\/\/www.incertitudes.fr\/book.pdf."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Alsuhibany, S.A. (2011, January 22\u201326). Optimising CAPTCHA generation. Proceedings of the 2011 Sixth International Conference on Availability, Reliability and Security, Washingot, DC, USA.","DOI":"10.1109\/ARES.2011.114"},{"key":"ref_37","unstructured":"Bursztein, E., Moscicki, A., Fabry, C., Bethard, S., Mitchell, J.C., and Jurafsky, D. (May, January 26). Easy does it: More usable CAPTCHAs. Proceedings of the Conference on Human Factors in Computing Systems-Proceedings, Toronto, CA, USA."},{"key":"ref_38","first-page":"1","article-title":"Keystroke Dynamics Authentication: A Survey of Free-text Methods","volume":"10","author":"Alsultan","year":"2013","journal-title":"Int. J. Comput. Sci."},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Killourhy, K.S., and Maxion, R.A. (2009, January 29). Comparing anomaly-detection algorithms for keystroke dynamics. Proceedings of the International Conference on Dependable Systems and Networks (DSN), Lisbon, Portugal.","DOI":"10.1109\/DSN.2009.5270346"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"191","DOI":"10.1049\/ise2.12018","article-title":"Detecting human attacks on text-based CAPTCHAs using the keystroke dynamic approach","volume":"15","author":"Alsuhibany","year":"2021","journal-title":"IET Inf. Secur."},{"key":"ref_41","unstructured":"Alsultan, A., Warwick, K., and Wei, H. (July, January 29). Improving the performance of free-text keystroke dynamics authentication by fusion. Proceedings of the 2009 IEEE\/IFIP International Conference on Dependable Systems & Networks, Lisbon, Portugal."},{"key":"ref_42","first-page":"95","article-title":"A Review on Authentication Methods","volume":"7","author":"Idrus","year":"2013","journal-title":"Aust. J. Basic Appl. Sci."}],"container-title":["Future Internet"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/3\/82\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T22:34:13Z","timestamp":1760135653000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1999-5903\/14\/3\/82"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,10]]},"references-count":42,"journal-issue":{"issue":"3","published-online":{"date-parts":[[2022,3]]}},"alternative-id":["fi14030082"],"URL":"https:\/\/doi.org\/10.3390\/fi14030082","relation":{},"ISSN":["1999-5903"],"issn-type":[{"value":"1999-5903","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,10]]}}}