Password Strength: An Empirical Analysis

被引:0
|
作者
Dell'Amico, Matteo [1 ]
Michiardi, Pietro [1 ]
Roudier, Yves [1 ]
机构
[1] Eurecom, Sophia Antipolis, France
关键词
SECURITY;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
It is a well known fact that user-chosen passwords are somewhat predictable: by using tools such as dictionaries or probabilistic models, attackers and password recovery tools can drastically reduce the number of attempts needed to guess a password. Quite surprisingly, however, existing literature does not provide a satisfying answer to the following question: given a number of guesses, what is the probability that a state-of-the-art attacker will be able to break a password? To answer the former question, we compare and evaluate the effectiveness of currently known attacks using various datasets of known passwords. We find that a "diminishing returns" principle applies: in the absence of an enforced password strength policy, weak passwords are common; on the other hand, as the attack goes on, the probability that a guess will succeed decreases by orders of magnitude. Even extremely powerful attackers won't be able to guess a substantial percentage of the passwords. The result of this work will help in evaluating the security of authentication means based on user-chosen passwords, and our methodology for estimating password strength can be used as a basis for creating more effective proactive password checkers for users and security auditing tools for administrators.
引用
收藏
页数:9
相关论文
共 50 条
  • [11] Weak Password Security: An Empirical Study
    Weber, James E.
    Guster, Dennis
    Safonov, Paul
    Schmidt, Mark B.
    INFORMATION SECURITY JOURNAL, 2008, 17 (01): : 45 - 54
  • [12] Password memorability and security: Empirical results
    Yan, J
    Blackwell, A
    Anderson, R
    Grant, A
    IEEE SECURITY & PRIVACY, 2004, 2 (05) : 25 - 31
  • [13] Password Security in Organizations: User Attitudes and Behaviors Regarding Password Strength
    Almehmadi, Tahani
    Alsolami, Fahad
    16TH INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY-NEW GENERATIONS (ITNG 2019), 2019, 800 : 9 - 13
  • [14] Beyond The Gates: An Empirical Analysis of HTTP-Managed Password Stealers and Operators
    Avgetidis, Athanasios
    Alrawi, Omar
    Valakuzhy, Kevin
    Lever, Charles
    Burbage, Paul
    Keromytis, Angelos D.
    Monrose, Fabian
    Antonakakis, Manos
    PROCEEDINGS OF THE 32ND USENIX SECURITY SYMPOSIUM, 2023, : 5307 - 5324
  • [15] Expectation Entropy as a Password Strength Metric
    Reaz, Khan
    Wunder, Gerhard
    2022 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2022,
  • [16] Effects of Peer Feedback on Password Strength
    Dupuis, Marc
    Khan, Faisal
    PROCEEDINGS OF THE 2018 APWG SYMPOSIUM ON ELECTRONIC CRIME RESEARCH (ECRIME), 2018, : 70 - 78
  • [17] An Explainable Online Password Strength Estimator
    David, Liron
    Wool, Avishai
    COMPUTER SECURITY - ESORICS 2021, PT I, 2021, 12972 : 285 - 304
  • [18] Designing Password Policies for Strength and Usability
    Shay, Richard
    Komanduri, Saranga
    Durity, Adam L.
    Huh, Phillip
    Mazurek, Michelle L.
    Segreti, Sean M.
    Ur, Blase
    Bauer, Lujo
    Christin, Nicolas
    Cranor, Lorrie Faith
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2016, 18 (04)
  • [19] Empirical Study of Secure Password Creation Habit
    Lo, Chloe Chun-Wing
    FOUNDATIONS OF AUGMENTED COGNITION: NEUROERGONOMICS AND OPERATIONAL NEUROSCIENCE, PT II, 2016, 9744 : 189 - 197
  • [20] An empirical study of mnemonic password creation tips
    Ye, Bei
    Guo, Yajun
    Zhang, Lei
    Guo, Xiaowei
    COMPUTERS & SECURITY, 2019, 85 : 41 - 50