Resilience of students' passwords against attacks

被引:0
|
作者
Brumen, Bostjan [1 ]
Makari, Tadej [1 ]
机构
[1] Univ Maribor, Fac Elect Engn & Comp Sci, Smetanova 17, SI-2000 Maribor, Slovenia
关键词
SECURITY; USERS;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Passwords are still the predominant mode of authentication in contemporary information systems, despite a long list of problems associated with their insecurity. Their primary advantage is the ease of use and the price of implementation, compared to other systems of authentication (e.g. two-factor, biometry,.). In this paper we present an analysis of passwords used by students of one of universities and their resilience against brute force and dictionary attacks. The passwords were obtained from a university's computing center in plaintext format for a very long period - first passwords were created before 1980. The results show that early passwords are extremely easy to crack: the percentage of cracked passwords is above 95 % for those created before 2006. Surprisingly, more than 40 % of passwords created in 2014 were easily broken within a few hours. The results show that users - in our case students, despite positive trends, still choose easy to break passwords. This work contributes to loud warnings that a shift from traditional password schemes to more elaborate systems is needed.
引用
收藏
页码:1275 / 1279
页数:5
相关论文
共 50 条
  • [21] Quantifying Cyberinfrastructure Resilience against Multi-Event Attacks
    Zobel, Christopher W.
    Khansa, Lara
    [J]. DECISION SCIENCES, 2012, 43 (04) : 685 - 710
  • [22] A measure of resilience against denial of service attacks in computer networks
    Sharafat, AR
    Fallah, MS
    [J]. COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2002, 17 (4-5): : 259 - 267
  • [23] Cyber Resilience: Why Protection against Cyber Attacks is not enough
    Kahrau, Felix
    [J]. ATP MAGAZINE, 2021, (11-12): : 32 - 34
  • [24] A logical framework for evaluating network resilience against faults and attacks
    Bursztein, Elie
    Goubault-Larrecq, Jean
    [J]. ADVANCES IN COMPUTER SCIENCE - ASIAN 2007: COMPUTER AND NETWORK SECURITY, PROCEEDINGS, 2007, 4846 : 212 - 227
  • [25] Multilayer Resilience Paradigm Against Cyber Attacks in DC Microgrids
    Sahoo, Subham
    Dragicevic, Tomislav
    Blaabjerg, Frede
    [J]. IEEE TRANSACTIONS ON POWER ELECTRONICS, 2021, 36 (03) : 2522 - 2532
  • [26] Enhancing RPL Resilience Against Routing Layer Insider Attacks
    Heurtefeux, Karel
    Erdene-Ochir, Ochirkhand
    Mohsin, Nasreen
    Menouar, Hamid
    [J]. 2015 IEEE 29TH INTERNATIONAL CONFERENCE ON ADVANCED INFORMATION NETWORKING AND APPLICATIONS (IEEE AINA 2015), 2015, : 802 - 807
  • [27] Resilience and Performance Analysis for State Estimation against Integrity Attacks
    Han, Duo
    Mu, Yilin
    Xie, Lihua
    [J]. IFAC PAPERSONLINE, 2016, 49 (22): : 55 - 60
  • [28] Against the odds: resilience in mathematics students in transition
    Hernandez-Martinez, Paul
    Williams, Julian
    [J]. BRITISH EDUCATIONAL RESEARCH JOURNAL, 2013, 39 (01) : 45 - 59
  • [29] Comparison of the Resilience of Convolutional and Cellular Neural Networks Against Adversarial Attacks
    Horvath, Andras
    [J]. 2022 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS 22), 2022, : 2348 - 2352
  • [30] Evaluating Resilience of Encrypted Traffic Classification against Adversarial Evasion Attacks
    Maarouf, Ramy
    Sattar, Danish
    Matrawy, Ashraf
    [J]. 26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,