首页> 外文期刊>IEEE transactions on dependable and secure computing >Achieving Flatness: Selecting the Honeywords from Existing User Passwords
【24h】

Achieving Flatness: Selecting the Honeywords from Existing User Passwords

机译:实现平坦度:从现有用户密码中选择蜜字

获取原文
获取原文并翻译 | 示例

摘要

Recently, Juels and Rivest proposed honeywords (decoy passwords) to detect attacks against hashed password databases. For each user account, the legitimate password is stored with several honeywords in order to sense impersonation. If honeywords are selected properly, a cyber-attacker who steals a file of hashed passwords cannot be sure if it is the real password or a honeyword for any account. Moreover, entering with a honeyword to login will trigger an alarm notifying the administrator about a password file breach. At the expense of increasing the storage requirement by 20 times, the authors introduce a simple and effective solution to the detection of password file disclosure events. In this study, we scrutinize the honeyword system and present some remarks to highlight possible weak points. Also, we suggest an alternative approach that selects the honeywords from existing user passwords in the system in order to provide realistic honeywords—a perfectly flat honeyword generation method—and also to reduce storage cost of the honeyword scheme.
机译:最近,Juels和Rivest提出了蜜字(诱骗密码)来检测对散列密码数据库的攻击。对于每个用户帐户,合法密码与几个蜜词一起存储,以感知假冒行为。如果正确选择了蜜字,则窃取散列密码文件的网络攻击者将无法确定它是真实密码还是任何帐户的蜜字。此外,使用蜜语输入进行登录将触发警报,通知管理员密码文件被破坏。以增加20倍的存储需求为代价,作者介绍了一种简单有效的解决方案来检测密码文件泄露事件。在这项研究中,我们仔细研究了honeyword系统,并提出了一些说明以突出可能的弱点。此外,我们建议一种替代方法,该方法从系统中现有的用户密码中选择蜜语,以提供逼真的蜜语(一种完美的扁平蜜语生成方法),并降低蜜语方案的存储成本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号