首页> 外文会议>IEEE Symposium on Security and Privacy >Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms
【24h】

Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms

机译:猜测(又一次又一次地):通过模拟密码开裂算法测量密码强度

获取原文

摘要

Text-based passwords remain the dominant authentication method in computer systems, despite significant advancement in attackers' capabilities to perform password cracking. In response to this threat, password composition policies have grown increasingly complex. However, there is insufficient research defining metrics to characterize password strength and using them to evaluate password-composition policies. In this paper, we analyze 12,000 passwords collected under seven composition policies via an online study. We develop an efficient distributed method for calculating how effectively several heuristic password-guessing algorithms guess passwords. Leveraging this method, we investigate (a) the resistance of passwords created under different conditions to guessing, (b) the performance of guessing algorithms under different training sets, (c) the relationship between passwords explicitly created under a given composition policy and other passwords that happen to meet the same requirements, and (d) the relationship between guess ability, as measured with password-cracking algorithms, and entropy estimates. Our findings advance understanding of both password-composition policies and metrics for quantifying password security.
机译:尽管攻击者的能力发生了密码开裂,但基于文本的密码仍然是计算机系统中的主导身份验证方法。为了响应这种威胁,密码组成政策已经增长越来越复杂。但是,没有足够的研究定义度量来表征密码强度并使用它们来评估密码组合策略。在本文中,我们通过在线学习分析了七项组成政策下收集的12,000密码。我们开发了一个有效的分布式方法,用于计算有效的多种启发式密码猜测算法猜测密码。利用这种方法,我们调查(a)在不同条件下创建的密码的阻力,(b)在不同训练集下的猜测算法的性能,(c)在给定的合成策略和其他密码下显式创建的密码之间的关系恰好满足相同的要求,(d)用密码开裂算法测量的猜测能力之间的关系,以及熵估计。我们的调查结果推进了对量化密码安全性的密码组合策略和指标的了解。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号