Password Strength: An Empirical Analysis

被引:0
|
作者
Dell'Amico, Matteo [1 ]
Michiardi, Pietro [1 ]
Roudier, Yves [1 ]
机构
[1] Eurecom, Sophia Antipolis, France
关键词
SECURITY;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
It is a well known fact that user-chosen passwords are somewhat predictable: by using tools such as dictionaries or probabilistic models, attackers and password recovery tools can drastically reduce the number of attempts needed to guess a password. Quite surprisingly, however, existing literature does not provide a satisfying answer to the following question: given a number of guesses, what is the probability that a state-of-the-art attacker will be able to break a password? To answer the former question, we compare and evaluate the effectiveness of currently known attacks using various datasets of known passwords. We find that a "diminishing returns" principle applies: in the absence of an enforced password strength policy, weak passwords are common; on the other hand, as the attack goes on, the probability that a guess will succeed decreases by orders of magnitude. Even extremely powerful attackers won't be able to guess a substantial percentage of the passwords. The result of this work will help in evaluating the security of authentication means based on user-chosen passwords, and our methodology for estimating password strength can be used as a basis for creating more effective proactive password checkers for users and security auditing tools for administrators.
引用
收藏
页数:9
相关论文
共 50 条
  • [31] Towards an Empirical Cost Model for Mental Password Algorithms
    Blanchard, Enka
    Selker, Ted
    Waligorski, Florentin
    CHI'20: EXTENDED ABSTRACTS OF THE 2020 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, 2020,
  • [32] Internet Protocol Cameras with No Password Protection: An Empirical Investigation
    Xu, Haitao
    Xu, Fengyuan
    Chen, Bo
    PASSIVE AND ACTIVE MEASUREMENT, PAM 2018, 2018, 10771 : 47 - 59
  • [33] Guess again (and again and again): Measuring password strength by simulating password-cracking algorithms
    Kelley, Patrick Gage
    Komanduri, Saranga
    Mazurek, Michelle L.
    Shay, Richard
    Vidas, Timothy
    Bauer, Lujo
    Christin, Nicolas
    Cranor, Lorrie Faith
    Lopez, Julio
    2012 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2012, : 523 - 537
  • [34] How Password Strength Becomes a Weak Link for Honeywords
    Vydelingum, Meaghen
    Martin, Miguel Vargas
    2023 11TH INTERNATIONAL CONFERENCE IN SOFTWARE ENGINEERING RESEARCH AND INNOVATION, CONISOFT 2023, 2023, : 99 - 107
  • [35] zxcvbn: Low-Budget Password Strength Estimation
    Wheeler, Daniel Lowe
    PROCEEDINGS OF THE 25TH USENIX SECURITY SYMPOSIUM, 2016, : 157 - 173
  • [36] A statistical Markov-based password strength meter
    Thai, Binh Le Thanh
    Tanaka, Hidema
    INTERNET OF THINGS, 2024, 25
  • [37] The Impact of Keyboard Type on Users' Perceptions of Password Strength
    Kortum, Philip
    Acemyan, Claudia Ziegler
    INTERNATIONAL JOURNAL OF TECHNOLOGY AND HUMAN INTERACTION, 2021, 17 (01) : 90 - 104
  • [38] GestureMeter: Design and Evaluation of a Gesture Password Strength Meter
    Cheon, Eunyong
    Huh, Jun Ho
    Oakley, Ian
    PROCEEDINGS OF THE 2023 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS (CHI 2023), 2023,
  • [39] Convenience or Strength? Aiding Optimal Strategies in Password Generation
    Stainbrook, Michael
    Caporusso, Nicholas
    ADVANCES IN HUMAN FACTORS IN CYBERSECURITY, AHFE 2018, 2019, 782 : 23 - 32
  • [40] Group Password Strength Meter Based on Attention Mechanism
    He, Daojing
    Zhou, Beibei
    Yang, Xiao
    Chan, Sammy
    Cheng, Yao
    Guiana, Nadra
    IEEE NETWORK, 2020, 34 (04): : 196 - 202