Strength Analysis of Real-Life Passwords Using Markov Models

被引:3
作者
Taneski, Viktor [1 ,2 ]
Kompara, Marko [1 ]
Hericko, Marjan [1 ]
Brumen, Bostjan [1 ]
机构
[1] Univ Maribor, Fac Elect Engn & Comp Sci, Maribor 2000, Slovenia
[2] Koroska Cesta 46, Maribor 2000, Slovenia
来源
APPLIED SCIENCES-BASEL | 2021年 / 11卷 / 20期
基金
欧盟地平线“2020”;
关键词
Markov models; passwords; password analysis; password strength; password score; SECURITY;
D O I
10.3390/app11209406
中图分类号
O6 [化学];
学科分类号
0703 ;
摘要
Recent literature proposes the use of a proactive password checker as method for preventing users from creating easy-to-guess passwords. Markov models can help us create a more effective password checker that would be able to check the probability of a given password to be chosen by an attacker. We investigate the ability of different Markov models to calculate a variety of passwords from different topics, in order to find out whether one Markov model is sufficient for creating a more effective password checker. The results of our study show that multiple models are required in order to be able to do strength calculations for a wide range of passwords. To the best of our knowledge, this is the first password strength study where the effect of the training password datasets on the success of the model is investigated.
引用
收藏
页数:32
相关论文
共 32 条
[1]  
[Anonymous], 2011, Large Password List: Free Download Dictionary File for Password Cracking
[2]  
[Anonymous], 2015, Passwords
[3]  
[Anonymous], 2015, Today I Am Releasing Ten Million Passwords
[4]  
[Anonymous], 2011, P 28 INT C INT C MAC, DOI DOI 10.5555/3104482.3104610
[5]  
[Anonymous], 2011, 10,000 Top Passwords
[6]  
[Anonymous], 2013, ARXIV, DOI DOI 10.48550/ARXIV.1308.0850
[7]   IMPROVING SYSTEM SECURITY VIA PROACTIVE PASSWORD CHECKING [J].
BISHOP, M ;
KLEIN, DV .
COMPUTERS & SECURITY, 1995, 14 (03) :233-249
[8]  
Castelluccia C., P 19 ANN NETW DISTR, VVolume 2012
[9]   Neural network techniques for proactive password checking [J].
Ciaramella, Angelo ;
D'Arco, Paolo ;
De Santis, Alfredo ;
Galdi, Clemente ;
Tagliaferri, Roberto .
IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2006, 3 (04) :327-339
[10]  
Cohen J, 1977, Statistical power analysis for the behavioral sciences, P1