USENIX Security2023Top-tier venue
Pass2Edit: A Multi-Step Generative Model for Guessing Edited Passwords
Ding Wang, Yunkai Zou, Yuan-an Xiao, Siqi Ma, Xiaofeng Chen
Abstract
While password stuffing attacks (that exploit the direct password reuse behavior) have gained considerable attention, only a few studies have examined password tweaking attacks, where an attacker exploits users' indirect reuse behaviors (with edit operations like insertion, deletion, and substitution). For the first time, we model the password tweaking attack as a multi-class classification problem for characterizing users' password edit/modification processes, and propose a generative model coupled with the multi-step decision-making mechanism, called PASS2EDIT, to accurately characterize users' password reuse/modification behaviors.
We demonstrate the effectiveness of PASS2EDIT through extensive experiments, which consist of 12 practical attack scenarios and employ 4.8 billion real-world passwords. The experimental results show that PASS2EDIT and its variant significantly improve over the prior art. More specifically, when the victim's password at site A (namely pw A ) is known, within 100 guesses, the cracking success rate of PASS2EDIT in guessing her password at site B (pw B =pw A ) is 24.2% (for common users) and 11.7% (for security-savvy users), respectively, which is 18.2%-33.0% higher than its foremost counterparts. Our results highlight that password tweaking is a much more damaging threat to password security than expected.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 777b081c-9d98-4fd5-95ee-b56857e56b34Cited by top-tier papers11
- PointerGuess: Targeted Password Guessing Model Using Pointer MechanismKedong Xiu, Ding WangUSENIX Security 2024 · 12 citations
- The Impact of Exposed Passwords on Honeyword EfficacyZonghao Huang, Lujo Bauer, Michael K. ReiterUSENIX Security 2024 · 7 citations
- A Security Analysis of Honey VaultsFei Duan, Ding Wang, Chunfu JiaS&P 2024 · 3 citations
- Targeted Password Guessing Using k-Nearest NeighborsZhen Li, Ding WangNDSS 2026 · 2 citations
- Credential Extraction Attacks Against Compromised Credential Checking Services of Password ManagersYihe Duan, Ding Wang, Yutong LiS&P 2026 · 1 citation
Builds on16
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri et al.USENIX Security 2016 · 331 citations
- How I Learned to be Secure: a Census-Representative Survey of Security Advice Sources and BehaviorElissa M. Redmiles, Sean Kross, Michelle L. MazurekCCS 2016 · 192 citations
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
Related papers
- Don't Forget the Stuffing! Revisiting the Security Impact of Typo-Tolerant Password AuthenticationSena Sahin, Frank LiCCS 2021 · 13 citations
- Password Guessing Using Random ForestDing Wang, Yunkai Zou, Zijian Zhang, Kedong XiuUSENIX Security 2023
- A Two-Decade Retrospective Analysis of a University's Vulnerability to Attacks Exploiting Reused PasswordsAlexandra Nisenoff, Maximilian Golla, Miranda Wei, Juliette Hainline et al.USENIX Security 2023
- RankGuess: Password Guessing Using Adversarial RankingTao Yang, Ding WangS&P 2025
- Might I Get Pwned: A Second Generation Compromised Credential Checking ServiceBijeeta Pal, Mazharul Islam, Marina Sanusi Bohuk, Nick Sullivan et al.USENIX Security 2022
