Password Strength: An Empirical Analysis

被引:0
|
作者
Dell'Amico, Matteo [1 ]
Michiardi, Pietro [1 ]
Roudier, Yves [1 ]
机构
[1] Eurecom, Sophia Antipolis, France
关键词
SECURITY;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
It is a well known fact that user-chosen passwords are somewhat predictable: by using tools such as dictionaries or probabilistic models, attackers and password recovery tools can drastically reduce the number of attempts needed to guess a password. Quite surprisingly, however, existing literature does not provide a satisfying answer to the following question: given a number of guesses, what is the probability that a state-of-the-art attacker will be able to break a password? To answer the former question, we compare and evaluate the effectiveness of currently known attacks using various datasets of known passwords. We find that a "diminishing returns" principle applies: in the absence of an enforced password strength policy, weak passwords are common; on the other hand, as the attack goes on, the probability that a guess will succeed decreases by orders of magnitude. Even extremely powerful attackers won't be able to guess a substantial percentage of the passwords. The result of this work will help in evaluating the security of authentication means based on user-chosen passwords, and our methodology for estimating password strength can be used as a basis for creating more effective proactive password checkers for users and security auditing tools for administrators.
引用
收藏
页数:9
相关论文
共 50 条
  • [1] On Password Strength Measurements: Password Entropy and Password Quality
    Taha, Mariam M.
    Alhaj, Taqwa A.
    Moktar, Ala E.
    Salim, Azza H.
    Abdullah, Settana M.
    2013 INTERNATIONAL CONFERENCE ON COMPUTING, ELECTRICAL AND ELECTRONICS ENGINEERING (ICCEEE), 2013, : 497 - 501
  • [2] Towards a Rigorous Statistical Analysis of Empirical Password Datasets
    Blocki, Jeremiah
    Liu, Peiyuan
    2023 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, SP, 2023, : 606 - 625
  • [3] Password Strength Measurement without Password Disclosure
    Sugai, Taku
    Ohigashi, Toshihiro
    Kakizaki, Yoshio
    Kanaoka, Akira
    2019 14TH ASIA JOINT CONFERENCE ON INFORMATION SECURITY (ASIAJCIS 2019), 2019, : 157 - 164
  • [4] Shadow Attacks Based on Password Reuses: A Quantitative Empirical Analysis
    Han, Weili
    Li, Zhigong
    Ni, Minyue
    Gu, Guofei
    Xu, Wenyuan
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2018, 15 (02) : 309 - 320
  • [5] An Empirical Analysis of Enterprise-Wide Mandatory Password Updates
    Mirian, Ariana
    Ho, Grant
    Savage, Stefan
    Voelker, Geoffrey M.
    39TH ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, ACSAC 2023, 2023, : 150 - 162
  • [6] The Security of Modern Password Expiration: An Algorithmic Framework and Empirical Analysis
    Zhang, Yinqian
    Monrose, Fabian
    Reiter, Michael K.
    PROCEEDINGS OF THE 17TH ACM CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'10), 2010, : 176 - 186
  • [7] Deep Learning for Password Guessing and Password Strength Evaluation, A Survey
    Zhang, Tao
    Cheng, Zelei
    Qin, Yi
    Li, Qiang
    Shi, Lin
    2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1163 - 1167
  • [8] LPSE: Lightweight password-strength estimation for password meters
    Guo, Yimin
    Zhang, Zhenfeng
    COMPUTERS & SECURITY, 2018, 73 : 507 - 518
  • [9] On the Accuracy of Password Strength Meters
    Golla, Maximilian
    Duermuth, Markus
    PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, : 1567 - 1582
  • [10] Password Strength Metre Application
    Boonkrong S.
    Kitthimon A.
    Koksoungnoen P.
    Jenprakhon K.
    International Journal of Interactive Mobile Technologies, 2021, 15 (15) : 59 - 73