USENIX Security2023Top-tier venue
Password Guessing Using Random Forest
Ding Wang, Yunkai Zou, Zijian Zhang, Kedong Xiu
Abstract
Passwords are the most widely used authentication method, and guessing attacks are the most effective method for password strength evaluation. However, existing password guessing models are generally built on traditional statistics or deep learning, and there has been no research on password guessing that employs classical machine learning. To fill this gap, this paper provides a brand new technical route for password guessing. More specifically, we re-encode the password characters and make it possible for a series of classical machine learning techniques that tackle multiclass classification problems (such as random forest, boosting algorithms and their variants) to be used for password guessing. Further, we propose RFGuess, a random-forest based framework that characterizes the three most representative password guessing scenarios (i.e., trawling guessing, targeted guessing based on personally identifiable information (PII) and on users' password reuse behaviors). Besides its theoretical significance, this work is also of practical value. Experiments using 13 large real-world password datasets demonstrate that our random-forest based guessing models are effective: (1) RFGuess for trawling guessing scenarios, whose guessing success rates are comparable to its foremost counterparts; (2) RFGuess-PII for targeted guessing based on PII, which guesses 20%∼28% of common users within 100 guesses, outperforming its foremost counterpart by 7%∼13%; (3) RFGuess-Reuse for targeted guessing based on users' password reuse/modification behaviors, which performs the best or 2nd best among related models. We believe this work makes a substantial step toward introducing classical machine learning techniques into password guessing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cfdf4681-297a-45ed-aecf-c1018d87db9bCited by top-tier papers6
- PointerGuess: Targeted Password Guessing Model Using Pointer MechanismKedong Xiu, Ding WangUSENIX Security 2024 · 12 citations
- Success Rates Doubled with Only One Character: Mask Password GuessingYunkai Zou, Ding Wang, Fei DuanNDSS 2026 · 1 citation
- MAYA: Addressing Inconsistencies in Generative Password Guessing Through a Unified BenchmarkWilliam Corrias, Fabio De Gaspari, Dorjan Hitaj, Luigi V. ManciniS&P 2026 · 1 citation
- Password Guessing Using Large Language ModelsYunkai Zou, Maoxiang An, Ding WangUSENIX Security 2025
- RankGuess: Password Guessing Using Adversarial RankingTao Yang, Ding WangS&P 2025
Builds on11
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan et al.NDSS 2018 · 1,102 citations
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri et al.USENIX Security 2016 · 331 citations
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 243 citations
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio et al.NDSS 2016 · 151 citations
Related papers
- Distinguishing Attacks from Legitimate Authentication Traffic at ScaleCormac Herley, Stuart E. SchechterNDSS 2019 · 15 citations
- MoPE: A Mixture of Password Experts for Improving Password GuessingMingjian Duan, Ming Xu, Shenghao Zhang, Weili HanS&P 2026
- CoT-DPG: A Co-Training based Dynamic Password Guessing MethodChenyang Wang, Fan Shi, Min Zhang, Chengxi Xu et al.NDSS 2026
- Targeted Password Guessing Using k-Nearest NeighborsZhen Li, Ding WangNDSS 2026 · 2 citations
- Improving Real-world Password Guessing Attacks via Bi-directional TransformersMing Xu, Jitao Yu, Xinyi Zhang, Chuanwang Wang et al.USENIX Security 2023
