Password and Passphrase Guessing with Recurrent Neural Networks

被引:0
|
作者
Alex Nosenko
Yuan Cheng
Haiquan Chen
机构
[1] Santa Clara County Office of Education,Department of Computer Science
[2] California State University,undefined
[3] Sacramento,undefined
来源
关键词
Authentication; Passwords; Passphrases; Recurrent neural networks;
D O I
暂无
中图分类号
学科分类号
摘要
Most online services continue their reliance on text-based passwords as the primary authentication mechanism. With a growing number of these services and the limited creativity to devise new memorable passwords, users tend to reuse their passwords across multiple platforms. These factors, combined with the increasing number of leaked passwords, make passwords vulnerable to cross-site guessing attacks. Over the years, researchers have proposed several prevalent methods to predict subsequently used passwords, such as dictionary attacks, rule-based approaches, neural networks, and combinations of the above. We exploit the correlation between the similarity and predictability of these subsequent passwords in a dataset of 28.8 million users and their 61.5 million passwords. We use a rule-based approach but delegate rule derivation, classification, and prediction to a Recurrent Neural Network (RNN). We limit the number of guessing attempts to ten yet get an astonishingly high prediction accuracy of up to 83% in under five attempts, twice as much as any other known model. The result makes our model effective for targeted online password guessing without getting spotted or locked out. To the best of our knowledge, this study is the first attempt of its kind using RNN. We also explore the use of RNN models in passphrase guessing. Passphrases are perceived to be more secure and easier to remember than passwords of the same length. We use a dataset that contains around 100,000 distinct phrases. We demonstrate that RNN models can predict complete passphrases given the initial word with rate up to 40%, which is twice better than other known approaches. Furthermore, our predictions can succeed in under 5,000 attempts, a 100% improvement compared to existing algorithms. In addition, this approach provides ease of deployment and low resource consumption. To our knowledge, it is the first attempt to exploit RNN for passphrase guessing.
引用
收藏
页码:549 / 565
页数:16
相关论文
共 50 条
  • [1] Password and Passphrase Guessing with Recurrent Neural Networks
    Nosenko, Alex
    Cheng, Yuan
    Chen, Haiquan
    [J]. INFORMATION SYSTEMS FRONTIERS, 2023, 25 (02) : 549 - 565
  • [2] Password Guessing Based on LSTM Recurrent Neural Networks
    Xu, Lingzhi
    Ge, Can
    Qiu, Weidong
    Huang, Zheng
    Guo, Jie
    Lian, Huijuan
    Gong, Zheng
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE) AND IEEE/IFIP INTERNATIONAL CONFERENCE ON EMBEDDED AND UBIQUITOUS COMPUTING (EUC), VOL 1, 2017, : 785 - 788
  • [3] Password Guessing Based on Recurrent Neural Networks and Generative Adversarial Networks
    Wang, Ding
    Zou, Yun-Kai
    Tao, Yi
    Wang, Bin
    [J]. Jisuanji Xuebao/Chinese Journal of Computers, 2021, 44 (08): : 1519 - 1534
  • [4] Learning Password Modification Patterns with Recurrent Neural Networks
    Nosenko, Alex
    Cheng, Yuan
    Chen, Haiquan
    [J]. SECURE KNOWLEDGE MANAGEMENT IN THE ARTIFICIAL INTELLIGENCE ERA, 2022, 1549 : 110 - 129
  • [5] CSNN: Password guessing method based on Chinese syllables and neural network
    Zhang, Yi
    Xian, Hequn
    Yu, Aimin
    [J]. PEER-TO-PEER NETWORKING AND APPLICATIONS, 2020, 13 (06) : 2237 - 2250
  • [6] CSNN: Password guessing method based on Chinese syllables and neural network
    Yi Zhang
    Hequn Xian
    Aimin Yu
    [J]. Peer-to-Peer Networking and Applications, 2020, 13 : 2237 - 2250
  • [7] GNPassGAN: Improved Generative Adversarial Networks For Trawling Offline Password Guessing
    Yu, Fangyi
    Martin, Miguel Vargas
    [J]. 7TH IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2022), 2022, : 10 - 18
  • [8] On Password Guessing with GPUs and FPGAs
    Duermuth, Markus
    Kranz, Thorsten
    [J]. TECHNOLOGY AND PRACTICE OF PASSWORDS, PASSWORDS'14, 2015, 9393 : 19 - 38
  • [9] Efficient Password Guessing based on a Password Segmentation Approach
    Deng, Gelei
    Yu, Xingjie
    Guo, Huaqun
    [J]. 2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [10] Threshold password authentication against guessing attacks in Ad hoc networks
    Chai, Zhenchuan
    Cao, Zhenfu
    Lu, Rongxing
    [J]. AD HOC NETWORKS, 2007, 5 (07) : 1046 - 1054