Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Passwords
Autor: | Shukun Yang, Shouling Ji, Weili Han, Xin Hu, Zhigong Li, Raheem Beyah |
---|---|
Rok vydání: | 2017 |
Předmět: |
Password
021110 strategic defence & security studies Password policy Cognitive password Computer science 0211 other engineering and technologies Password cracking 020206 networking & telecommunications 02 engineering and technology Computer security computer.software_genre One-time password Password strength S/KEY ComputingMilieux_MANAGEMENTOFCOMPUTINGANDINFORMATIONSYSTEMS 0202 electrical engineering electronic engineering information engineering Electrical and Electronic Engineering computer Password psychology |
Zdroj: | IEEE Transactions on Dependable and Secure Computing. 14:550-564 |
ISSN: | 1545-5971 |
Popis: | In this paper, we conduct a large-scale study on the crackability, correlation, and security of ${\sim}145$ million real world passwords, which were leaked from several popular Internet services and applications. To the best of our knowledge, this is the largest empirical study that has been conducted. Specifically, we first evaluate the crackability of ${\sim}145$ million real world passwords against 6+ state-of-the-art password cracking algorithms in multiple scenarios. Second, we examine the effectiveness and soundness of popular commercial password strength meters (e.g., Google, QQ) and the security impacts of username/email leakage on passwords. Finally, we discuss the implications of our results, analysis, and findings, which are expected to help both password users and system administrators to gain a deeper understanding of the vulnerability of real passwords against state-of-the-art password cracking algorithms, as well as to shed light on future password security research topics. |
Databáze: | OpenAIRE |
Externí odkaz: |