Interpretable Probabilistic Password Strength Meters via Deep Learning

被引:9
|
作者
Pasquini, Dario [1 ,2 ,3 ]
Ateniese, Giuseppe [1 ]
Bernaschi, Massimo [3 ]
机构
[1] Stevens Inst Technol, Hoboken, NJ 07030 USA
[2] Sapienza Univ Rome, Rome, Italy
[3] CNR, Inst Appl Comp, Rome, Italy
来源
关键词
Password security; Strength meters; Deep learning;
D O I
10.1007/978-3-030-58951-6_25
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Probabilistic password strength meters have been proved to be the most accurate tools to measure password strength. Unfortunately, by construction, they are limited to solely produce an opaque security estimation that fails to fully support the user during the password composition. In the present work, we move the first steps towards cracking the intelligibility barrier of this compelling class of meters. We show that probabilistic password meters inherently own the capability to describe the latent relation between password strength and password structure. In our approach, the security contribution of each character composing a password is disentangled and used to provide explicit fine-grained feedback for the user. Furthermore, unlike existing heuristic constructions, our method is free from any human bias, and, more importantly, its feedback has a clear probabilistic interpretation. In our contribution: (1) we formulate the theoretical foundations of interpretable probabilistic password strength meters; (2) we describe how they can be implemented via an efficient and lightweight deep learning framework suitable for client-side operability.
引用
收藏
页码:502 / 522
页数:21
相关论文
共 50 条
  • [1] On the Accuracy of Password Strength Meters
    Golla, Maximilian
    Duermuth, Markus
    PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 1567 - 1582
  • [2] Deep Learning for Password Guessing and Password Strength Evaluation, A Survey
    Zhang, Tao
    Cheng, Zelei
    Qin, Yi
    Li, Qiang
    Shi, Lin
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1163 - 1167
  • [3] Interpretable Deep Learning for Probabilistic MJO Prediction
    Delaunay, Antoine
    Christensen, Hannah M.
    GEOPHYSICAL RESEARCH LETTERS, 2022, 49 (16)
  • [4] LPSE: Lightweight password-strength estimation for password meters
    Guo, Yimin
    Zhang, Zhenfeng
    COMPUTERS & SECURITY, 2018, 73 : 507 - 518
  • [5] A probabilistic approach for interpretable deep learning in liver cancer diagnosis
    Wang, Clinton J.
    Hamm, Charlie A.
    Letzen, Brian S.
    Duncan, James S.
    MEDICAL IMAGING 2019: COMPUTER-AIDED DIAGNOSIS, 2019, 10950
  • [6] Privacy-Preserving Password Strength Meters with FHE
    Emmadi, Nitesh
    Shaik, Imtiyazuddin
    Tupsamudre, Harshal
    Narumanchi, Harika
    Bhattachar, Rajan Mindigal Alasingara
    Lodha, Sachin Premsukh
    CYBER SECURITY CRYPTOGRAPHY AND MACHINE LEARNING, 2021, 12716 : 94 - 103
  • [7] A Study on Markov-Based Password Strength Meters
    Thai, Binh Le Thanh
    Tanaka, Hidema
    IEEE ACCESS, 2024, 12 : 69066 - 69075
  • [8] Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries
    Pasquini, Dario
    Cianfriglia, Marco
    Ateniese, Giuseppe
    Bernaschi, Massimo
    PROCEEDINGS OF THE 30TH USENIX SECURITY SYMPOSIUM, 2021, : 821 - 838
  • [9] A probabilistic Framework for Improved Password Strength Metrics
    Galbally, Javier
    Coisel, Iwen
    Sanchez, Ignacio
    2014 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2014,
  • [10] Interpretable Deep Learning Prediction Model for Compressive Strength of Concrete
    Zhang, Wei-Qi
    Wang, Hui-Ming
    Dongbei Daxue Xuebao/Journal of Northeastern University, 2024, 45 (05): : 738 - 744