【24h】

IDENTIFYING PASSWORDS STORED ON DISK

机译:识别存储在磁盘上的密码

获取原文

摘要

This chapter presents a solution to the problem of identifying passwords on storage media. Because of the proliferation of websites for finance, commerce and entertainment, the typical user today often has to store passwords on a computer hard drive. The identification problem is to find strings on the disk that are likely to be passwords. Automated identification is very useful to digital forensic investigators who need to recover potential passwords when working on cases. The problem is nontrivial because a hard disk typically contains numerous strings. The chapter describes a novel approach that determines a good set of candidate strings in which stored passwords are very likely to be found. This is accomplished by first examining the disk for tokens (potential password strings) and applying filtering algorithms to winnow down the tokens to a more manageable set. Next, a probabilistic context-free grammar is used to assign probabilities to the remaining tokens. The context-free grammar is derived via training with a set of revealed passwords. Three algorithms are used to rank the tokens after filtering. Experiments reveal that one of the algorithms, the one-by-one algorithm, returns a password-rich set of 2,000 tokens culled from more than 49 million tokens on a large-capacity drive. Thus, a forensic investigator would only have to test a small set of tokens that would likely contain many of the stored passwords.
机译:本章介绍了在存储介质上识别密码的问题。由于融资,商业和娱乐网站的扩散,今天的典型用户通常必须在计算机硬盘上存储密码。识别问题是在可能是密码的磁盘上找到字符串。自动识别对于在案件上时需要恢复潜在密码的数字法医调查人员非常有用。问题是非虚拟的,因为硬盘通常包含许多字符串。本章介绍了一种新的方法,它决定了一组很可能找到存储密码的良好候选字符串。这是通过首先检查令牌的磁盘(潜在密码字符串)并将滤波算法应用于WinNowownow到更可管理的集合来实现。接下来,使用概率的无背景语法用于将概率分配给剩余的令牌。通过培训使用一组显示的密码来派生无规文语法。三种算法用于过滤后对令牌进行排序。实验表明,这些算法之一,一个接一个的算法,返回了丰富的密码组来自以及超过4,900万种令牌的大容量硬盘扑杀2000个令牌。因此,法医调查员只能测试可能包含许多存储密码的一小组令牌。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号