论文标题

失去披露:关于密码组成政策的推断

Lost in Disclosure: On The Inference of Password Composition Policies

论文作者

Johnson, Saul, Ferreira, João, Mendes, Alexandra, Cordry, Julien

论文摘要

大规模密码数据泄露事件变得越来越普遍,这使研究人员能够利用现实世界密码数据集生产大量密码安全研究,这些密码数据集通常包含数千数甚至千万的记录。尽管已经对密码组成策略(用户在创建密码时必须遵守的一组规则)进行了大量研究,影响了在系统上用户选择密码的分布,但对于推断给定的一组用户选择的密码创建的密码组成策略的研究却少得多。在本文中,我们指出了针对这一挑战的天真方法的问题,并提出了一种简单的方法,可以产生更可靠的结果。我们还提出了Pol-Anfer,这是一种实现此方法的工具,并展示了其在推断密码组成策略中的使用。

Large-scale password data breaches are becoming increasingly commonplace, which has enabled researchers to produce a substantial body of password security research utilising real-world password datasets, which often contain numbers of records in the tens or even hundreds of millions. While much study has been conducted on how password composition policies (sets of rules that a user must abide by when creating a password) influence the distribution of user-chosen passwords on a system, much less research has been done on inferring the password composition policy that a given set of user-chosen passwords was created under. In this paper, we state the problem with the naive approach to this challenge, and suggest a simple approach that produces more reliable results. We also present pol-infer, a tool that implements this approach, and demonstrates its use in inferring password composition policies.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源