Measuring Real-World Accuracies and Biases in Modeling Password Guessability
@inproceedings{Ur2015MeasuringRA, title={Measuring Real-World Accuracies and Biases in Modeling Password Guessability}, author={B. Ur and Sean M. Segreti and L. Bauer and N. Christin and L. Cranor and Saranga Komanduri and D. Kurilova and Michelle L. Mazurek and William Melicher and R. Shay}, booktitle={USENIX Security Symposium}, year={2015} }
Parameterized password guessability--how many guesses a particular cracking algorithm with particular training data would take to guess a password--has become a common metric of password security. Unlike statistical metrics, it aims to model real-world attackers and to provide per-password strength estimates. We investigate how cracking approaches often used by researchers compare to real-world cracking by professionals, as well as how the choice of approach biases research conclusions.
We… CONTINUE READING
Figures, Tables, and Topics from this paper
128 Citations
Fast, Lean, and Accurate: Modeling Password Guessability Using Neural Networks
- Computer Science
- USENIX Annual Technical Conference
- 2016
- 142
- PDF
Reasoning Analytically about Password-Cracking Software
- Computer Science
- 2019 IEEE Symposium on Security and Privacy (SP)
- 2019
- 2
- PDF
Convergence of Password Guessing to Optimal Success Rates †
- Computer Science, Medicine
- Entropy
- 2020
- 2
- PDF
Password Guessers Under a Microscope: An In-Depth Analysis to Inform Deployments
- Computer Science
- ArXiv
- 2020
- PDF
Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries
- Computer Science
- ArXiv
- 2020
- 1
- Highly Influenced
- PDF
References
SHOWING 1-10 OF 84 REFERENCES
Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms
- Computer Science
- 2012 IEEE Symposium on Security and Privacy
- 2012
- 376
- PDF
When Privacy meets Security: Leveraging personal information for password cracking
- Computer Science
- ArXiv
- 2013
- 57
- PDF
Password Strength: An Empirical Analysis
- Computer Science
- 2010 Proceedings IEEE INFOCOM
- 2010
- 236
- Highly Influential
- PDF
The Science of Guessing: Analyzing an Anonymized Corpus of 70 Million Passwords
- Computer Science
- 2012 IEEE Symposium on Security and Privacy
- 2012
- 627
- Highly Influential
- PDF
A Study of Probabilistic Password Models
- Computer Science
- 2014 IEEE Symposium on Security and Privacy
- 2014
- 186
- Highly Influential
- PDF
From Very Weak to Very Strong: Analyzing Password-Strength Meters
- Computer Science
- NDSS
- 2014
- 137
- Highly Influential
- PDF
Password Cracking Using Probabilistic Context-Free Grammars
- Computer Science
- 2009 30th IEEE Symposium on Security and Privacy
- 2009
- 384
- PDF