论文标题

显微镜下的密码猜测者:深入分析以告知部署

Password Guessers Under a Microscope: An In-Depth Analysis to Inform Deployments

论文作者

Parish, Zach, Cushing, Connor, Aggarwal, Shourya, Salehi-Abari, Amirali, Thorpe, Julie

论文摘要

密码猜测者有助于评估密码的强度。尽管它们的多样性和丰富性,但对猜测者的彼此相比鲜为人知,知之甚少。我们对密码猜测者的猜测能力和行为进行了深入的分析和比较。为了扩展分析超出破解密码的数量,我们设计了一个分析框架,以比较猜测者在各种条件下生成的密码类型(例如,有限的培训数据,有限的猜测以及不同的培训和目标培训和目标数据)。我们的结果表明,即使在相同的数据上训练时,猜测者通常会产生不同的猜测。我们利用这一结果表明,计算刻薄的猜测者的组合与计算密集型猜测者一样有效,但效率更高。我们的见解使我们能够在执行密码检查时为系统管理员提供一套具体的建议。

Password guessers are instrumental for assessing the strength of passwords. Despite their diversity and abundance, little is known about how different guessers compare to each other. We perform in-depth analyses and comparisons of the guessing abilities and behavior of password guessers. To extend analyses beyond number of passwords cracked, we devise an analytical framework to compare the types of passwords that guessers generate under various conditions (e.g., limited training data, limited number of guesses, and dissimilar training and target data). Our results show that guessers often produce dissimilar guesses, even when trained on the same data. We leverage this result to show that combinations of computationally-cheap guessers are as effective as computationally intensive guessers, but more efficient. Our insights allow us to provide a concrete set of recommendations for system administrators when performing password checking.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源