A CAPTCHA-gated registration scheme with sequences of reCAPTCHAs at random intervals and short solve windows limits automated censor deployment. With 5 minutes spent per registration, a human adversary working non-stop for 24 hours can create at most 288 censors; combined with a 12-hour registration reset cycle, this bounds the adversary's censor accumulation rate.
From 2017-heydari-scalable — Scalable Anti-Censorship Framework Using Moving Target Defense for Web Servers
· §IV-B
· 2017
· Transactions on Information Forensics and Security
Implications
Registration rate-limiting via time-gated multi-step CAPTCHAs is a necessary complement to IP rotation — without it, adversaries can automate censor provisioning at a rate that overwhelms the swarming ratio defense.
Periodic global registration resets (e.g., every 12 hours) amortize the human cost of censor maintenance, forcing adversaries to repeat expensive registration for every censor at each reset, not just at initial deployment.