Measuring Real-World Accuracies and Biases in Modeling Password Guessability

Measuring Real-World Accuracies and Biases in Modeling Password Guessability
复制标题

DOI:
--
复制
发表时间:
2015-08
期刊:
--
影响因子:
--
通讯作者:
Blase Ur;Sean M. Segreti;Lujo Bauer;Nicolas Christin;L. Cranor;Saranga Komanduri;Darya Kurilova;
Blase Ur;Sean M. Segreti;Lujo Bauer;Nicolas Christin;L. Cranor;Saranga Komanduri;Darya Kurilova;
中科院分区:
其他
文献类型:
--
作者:
Blase Ur;Sean M. Segreti;Lujo Bauer;Nicolas Christin;L. Cranor;Saranga Komanduri;Darya Kurilova;

文献摘要

被引文献

相似文献

参数化的密码可猜测性--使用特定训练数据的特定破解算法需要多少次猜测才能猜出密码--已经成为密码安全性的常用度量。与统计指标不同,它旨在模拟真实世界的攻击者,并提供每个密码的强度估计。我们调查了研究人员经常使用的破解方法与专业人士的真实破解方法的比较,以及方法的选择如何影响研究结论。我们发现,专业人士的半自动破解优于流行的全自动方法,但可以通过组合多种此类方法来近似。然而,这些方法只有在仔细配置和调优的情况下才有效;在常用的默认配置中,它们低估了密码在现实世界中的可猜测性。我们发现,大型密码集的分析往往是强大的算法用于猜测,只要它是有效地配置。然而,破解算法在它们的有效性上系统地不同,猜测具有某些共同特征的密码(例如,字符替换)。这对于分析特定密码特征或单个密码(例如,在密码计量器或安全审计中)。我们的研究结果强调了仅依赖单一破解算法作为密码强度度量的危险,并构成了第一个科学证据,即自动猜测通常可以近似于专业人士的猜测。
Parameterized password guessability--how many guesses a particular cracking algorithm with particular training data would take to guess a password--has become a common metric of password security. Unlike statistical metrics, it aims to model real-world attackers and to provide per-password strength estimates. We investigate how cracking approaches often used by researchers compare to real-world cracking by professionals, as well as how the choice of approach biases research conclusions. We find that semi-automated cracking by professionals outperforms popular fully automated approaches, but can be approximated by combining multiple such approaches. These approaches are only effective, however, with careful configuration and tuning; in commonly used default configurations, they underestimate the real-world guessability of passwords. We find that analyses of large password sets are often robust to the algorithm used for guessing as long as it is configured effectively. However, cracking algorithms differ systematically in their effectiveness guessing passwords with certain common features (e.g., character substitutions). This has important implications for analyzing the security of specific password characteristics or of individual passwords (e.g., in a password meter or security audit). Our results highlight the danger of relying only on a single cracking algorithm as a measure of password strength and constitute the first scientific evidence that automated guessing can often approximate guessing by professionals.