The Next Domino to Fall: Empirical Analysis of User Passwords across Online Services

The Next Domino to Fall: Empirical Analysis of User Passwords across Online Services
复制标题

DOI:
10.1145/3176258.3176332
复制
发表时间:
2018-03
期刊:
Proceedings of the Eighth ACM Conference on Data and Application Security and Privacy
影响因子:
--
通讯作者:
C. Wang;Steve T. K. Jan;Hang Hu;Douglas Bossart;G. Wang
C. Wang;Steve T. K. Jan;Hang Hu;Douglas Bossart;G. Wang
中科院分区:
其他
文献类型:
--
作者:
C. Wang;Steve T. K. Jan;Hang Hu;Douglas Bossart;G. Wang

文献摘要

被引文献

相似文献

如果用户重复使用或稍微修改其他服务的密码,则因数据泄露而泄露的密码可能会造成严重威胁。如今,随着越来越多的服务遭到破坏,人们仍然缺乏对这种风险的定量理解。在本文中,我们使用 8 年来 107 个服务中 2880 万用户及其 6150 万个密码的真实数据集,对密码重用和修改模式进行了首次大规模实证分析。我们发现密码重复使用和修改非常常见(在 52% 的用户中观察到)。购物网站和电子邮件服务等敏感在线服务的密码重复使用和修改次数最多。我们还观察到,在最初的数据泄露后的数年里,用户仍然会重复使用其他在线服务已经泄露的密码。最后,为了量化安全风险,我们开发了一种新的基于训练的猜测算法。我们表明,只需 10 次猜测,就可以破解超过 1600 万个密码对(包括 30% 的修改密码)。
Leaked passwords from data breaches can pose a serious threat if users reuse or slightly modify the passwords for other services. With more services getting breached today, there is still a lack of a quantitative understanding of this risk. In this paper, we perform the first large-scale empirical analysis of password reuse and modification patterns using a ground-truth dataset of 28.8 million users and their 61.5 million passwords in 107 services over 8 years. We find that password reuse and modification is very common (observed on 52% of the users). Sensitive online services such as shopping websites and email services received the most reused and modified passwords. We also observe that users would still reuse the already-leaked passwords for other online services for years after the initial data breach. Finally, to quantify the security risks, we develop a new training-based guessing algorithm. We show that more than 16 million password pairs (including 30% of the modified passwords) can be cracked within just 10 guesses.