Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Passwords

被引:28
作者
Ji, Shouling [1 ,2 ]
Yang, Shukun [2 ]
Hu, Xin [3 ]
Han, Weili [4 ]
Li, Zhigong [4 ]
Beyah, Raheem [2 ]
机构
[1] Zhejiang Univ, Coll Comp Sci & Technol, Hangzhou 310027, Zhejiang, Peoples R China
[2] Georgia Inst Technol, Sch Elect & Comp Engn, Atlanta, GA 30332 USA
[3] IBM Corp, TJ Watson Res Ctr, Armonk, NY 10504 USA
[4] Fudan Univ, Software Sch, Shanghai, Peoples R China
关键词
Passwords; evaluation; crackability; classification; correlation; password meter; password strength;
D O I
10.1109/TDSC.2015.2481884
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we conduct a large-scale study on the crackability, correlation, and security of similar to 145 million real world passwords, which were leaked from several popular Internet services and applications. To the best of our knowledge, this is the largest empirical study that has been conducted. Specifically, we first evaluate the crackability of similar to 145 million real world passwords against 6+ state-of-the-art password cracking algorithms in multiple scenarios. Second, we examine the effectiveness and soundness of popular commercial password strength meters (e.g.,Google, QQ) and the security impacts of username/email leakage on passwords. Finally, we discuss the implications of our results, analysis, and findings, which are expected to help both password users and system administrators to gain a deeper understanding of the vulnerability of real passwords against state-of-the-art password cracking algorithms, as well as to shed light on future password security research topics.
引用
收藏
页码:550 / 564
页数:15
相关论文
empty
未找到相关数据