USENIX Security2023Top-tier venue
Araña: Discovering and Characterizing Password Guessing Attacks in Practice
Mazharul Islam, Marina Sanusi Bohuk, Paul Chung, Thomas Ristenpart, Rahul Chatterjee
Abstract
Remote password guessing attacks remain one of the largest sources of account compromise. Understanding and characterizing attacker strategies is critical to improving security, but doing so has been challenging thus far due to the sensitivity of login services and the lack of ground truth labels for benign and malicious login requests. We perform an in-depth measurement study of guessing attacks targeting two large universities. Using a rich dataset of more than 34 million login requests to the two universities as well as thousands of compromise reports, we were able to develop a new analysis pipeline to identify 29 attack clusters-many of which involved compromises not previously known to security engineers. Our analysis provides the richest investigation to date of password guessing attacks as seen from login services. We believe our tooling will be useful in future efforts to develop real-time detection of attack campaigns, and our characterization of attack campaigns can help more broadly guide mitigation design.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext dca526f5-a43f-41b1-b5a6-dcaefc7840f3Cited by top-tier papers3
- Targeted Password Guessing Using k-Nearest NeighborsZhen Li, Ding WangNDSS 2026 · 2 citations
- Preventing Artificially Inflated SMS Attacks through Large-Scale Traffic InspectionJun Ho Huh, Hyejin Shin, Sunwoo Ahn, Hayoon Yi et al.USENIX Security 2025
- Detecting Compromise of Passkey Storage on the CloudMazharul Islam, Sunpreet S. Arora, Rahul Chatterjee, Ke Coby WangUSENIX Security 2025
Builds on10
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett et al.CCS 2017 · 248 citations
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio et al.NDSS 2016 · 151 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
Related papers
- A Two-Decade Retrospective Analysis of a University's Vulnerability to Attacks Exploiting Reused PasswordsAlexandra Nisenoff, Maximilian Golla, Miranda Wei, Juliette Hainline et al.USENIX Security 2023
- Distinguishing Attacks from Legitimate Authentication Traffic at ScaleCormac Herley, Stuart E. SchechterNDSS 2019 · 15 citations
- Gossamer: Securely Measuring Password-based LoginsMarina Sanusi Bohuk, Mazharul Islam, Suleman Ahmad, Michael M. Swift et al.USENIX Security 2022
- Inconsistent, Incomplete, and Insecure: A Survey of Account Security InterfacesArkaprabha Bhattacharya, Alaa Daffalla, Kevin Lee, Rosanna Bellini et al.USENIX Security 2026
- Password Guessing Using Random ForestDing Wang, Yunkai Zou, Zijian Zhang, Kedong XiuUSENIX Security 2023
