USENIX Security2024Top-tier venue
PointerGuess: Targeted Password Guessing Model Using Pointer Mechanism
Kedong Xiu, Ding Wang
Abstract
Most existing targeted password guessing models view users' reuse behaviors as sequences of edit operations (e.g., insert and delete) performed on old passwords. These atomic edit operations are limited to modifying one character at a time and cannot fully cover users' complex password modification behaviors (e.g., modifying the password structure). This partially leads to a significant gap between the proportion of users' reused passwords and the success rates that existing targeted password models can achieve. To fill this gap, this paper models users' reuse behaviors by focusing on two key components: (1) What they want to copy/keep; (2) What they want to tweak. More specifically, we introduce the pointer mechanism and propose a new targeted guessing model, namely POINT-ERGUESS. By hierarchically redefining password reuse from both personal and population-wide perspectives, we can accurately and comprehensively characterize users' password reuse behaviors. Moreover, we propose MS-POINTERGUESS, which can employ the victim's multiple leaked passwords. By employing 13 large-scale real-world password datasets, we demonstrate that POINTERGUESS is effective: (1) When the victim's password at site A (namely pw A ) is known, within 100 guesses, the average success rate of POINTERGUESS in guessing her password at site B (namely pw B , pw A = pw B ) is 25.21% (for common users) and 12.34% (for security-savvy users), respectively, which is 21.23%∼71.54% (38.37% on average) higher than its foremost counterparts; (2) When not excluding identical password pairs (i.e., pw A can equal pw B ), within 100 guesses, the average success rate of POINT-ERGUESS is 48.30% (for common users) and 28.42% (for security-savvy users), respectively, which is 6.31%∼15.92% higher than its foremost counterparts; (3) Within 100 guesses, the MS-POINTERGUESS further improves the cracking success rate by 31.21% compared to POINTERGUESS.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f2252dfb-a3c0-4c3b-9f6f-0d6d42d5e6f9Cited by top-tier papers6
- Targeted Password Guessing Using k-Nearest NeighborsZhen Li, Ding WangNDSS 2026 · 2 citations
- Credential Extraction Attacks Against Compromised Credential Checking Services of Password ManagersYihe Duan, Ding Wang, Yutong LiS&P 2026 · 1 citation
- Success Rates Doubled with Only One Character: Mask Password GuessingYunkai Zou, Ding Wang, Fei DuanNDSS 2026 · 1 citation
- Password Guessing Using Large Language ModelsYunkai Zou, Maoxiang An, Ding WangUSENIX Security 2025
- "Who is Trying to Access My Account?" Exploring User Perceptions and Reactions to Risk-based Authentication NotificationsTongxin Wei, Ding Wang, Yutong Li, Yuehuan WangNDSS 2025
Builds on12
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 243 citations
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
- Improving Password Guessing via Representation LearningDario Pasquini, Ankit Gangwal, Giuseppe Ateniese, Massimo Bernaschi et al.S&P 2021 · 101 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
Related papers
- Pass2Edit: A Multi-Step Generative Model for Guessing Edited PasswordsDing Wang, Yunkai Zou, Yuan-an Xiao, Siqi Ma et al.USENIX Security 2023
- Password Guessing Using Random ForestDing Wang, Yunkai Zou, Zijian Zhang, Kedong XiuUSENIX Security 2023
- A Two-Decade Retrospective Analysis of a University's Vulnerability to Attacks Exploiting Reused PasswordsAlexandra Nisenoff, Maximilian Golla, Miranda Wei, Juliette Hainline et al.USENIX Security 2023
- RankGuess: Password Guessing Using Adversarial RankingTao Yang, Ding WangS&P 2025
- MoPE: A Mixture of Password Experts for Improving Password GuessingMingjian Duan, Ming Xu, Shenghao Zhang, Weili HanS&P 2026
