On the Implications of Zipf's Law in Passwords

被引:47
|
作者
Wang, Ding [1 ]
Wang, Ping [1 ,2 ]
机构
[1] Peking Univ, Sch EECS, Beijing 100871, Peoples R China
[2] Peking Univ, Sch Software & Microelect, Beijing 100260, Peoples R China
来源
关键词
AUTHENTICATION; EFFICIENT;
D O I
10.1007/978-3-319-45744-4_6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Textual passwords are perhaps the most prevalent mechanism for access control over the Internet. Despite the fact that human-beings generally select passwords in a highly skewed way, it has long been assumed in the password research literature that users choose passwords randomly and uniformly. This is partly because it is easy to derive concrete (numerical) security results under the uniform assumption, and partly because we do not know what's the exact distribution of passwords if we do not make a uniform assumption. Fortunately, researchers recently reveal that user-chosen passwords generally follow the Zipf's law, a distribution which is vastly different from the uniform one. In this work, we explore a number of foundational security implications of the Zipf-distribution assumption about passwords. Firstly, we how the attacker's advantages against password-based cryptographic protocols (e.g., authentication, encryption, signature and secret share) can be 2-4 orders of magnitude more accurately captured (formulated) than existing formulation results. As password protocols are the most widely used cryptographic protocols, our new formulation is of practical significance. Secondly, we provide new insights into popularity-based password creation policies and point out that, under the current, widely recommended security parameters, usability will be largely impaired. Thirdly, we show that the well-known password strength metric a-guesswork, which was believed to be parametric, is actually non-parametric in two of four cases under the Zipf assumption. Particularly, nine large-scale, real-world password datasets are employed to establish the practicality of our findings.
引用
收藏
页码:111 / 131
页数:21
相关论文
共 50 条
  • [41] Some Properties of Zipf's Law and Applications
    Bolea, Speranta Cecilia
    Pirnau, Mironela
    Bejinariu, Silviu-Ioan
    Apopei, Vasile
    Gifu, Daniela
    Teodorescu, Horia-Nicolai
    AXIOMS, 2024, 13 (03)
  • [42] To Be Or Not To Be IID: Can Zipf's Law Help?
    Behe, Leo
    Wheeler, Zachary
    Nelson, Christie
    Knopp, Brian
    Pottenger, William M.
    2015 IEEE INTERNATIONAL SYMPOSIUM ON TECHNOLOGIES FOR HOMELAND SECURITY (HST), 2015,
  • [43] Asymptotically Normal Estimators for Zipf's Law
    Chebunin, Mikhail
    Kovalevskii, Artyom
    SANKHYA-SERIES A-MATHEMATICAL STATISTICS AND PROBABILITY, 2019, 81 (02): : 482 - 492
  • [44] Zipf's law holds for phrases, not words
    Williams, Jake Ryland
    Lessard, Paul R.
    Desu, Suma
    Clark, Eric M.
    Bagrow, James P.
    Danforth, Christopher M.
    Dodds, Peter Sheridan
    SCIENTIFIC REPORTS, 2015, 5
  • [45] Zipf's law, music classification, and aesthetics
    Manaris, B
    Romero, J
    Machado, P
    Krehbiel, D
    Hirzel, T
    Pharr, W
    Davis, RB
    COMPUTER MUSIC JOURNAL, 2005, 29 (01) : 55 - 69
  • [46] Deformed Zipf's law in personal donation
    Chen, Q.
    Wang, C.
    Wang, Y.
    EPL, 2009, 88 (03)
  • [47] Refinement of Zipf's law for frequency dictionaries
    Maslov, VP
    DOKLADY MATHEMATICS, 2005, 72 (03) : 942 - 945
  • [48] Zipf's law: A viable geological paradigm?
    Merriam D.F.
    Drew L.J.
    Schuenemeyer J.H.
    Natural Resources Research, 2004, 13 (4) : 265 - 271
  • [49] True reason for Zipf's law in language
    Wang, DH
    Li, MH
    Di, ZR
    PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2005, 358 (2-4) : 545 - 550
  • [50] The end of a paradigm: is Zipf's law universal?
    Benguigui, L.
    Blumenfeld-Lieberthal, E.
    JOURNAL OF GEOGRAPHICAL SYSTEMS, 2011, 13 (01) : 87 - 100