USENIX Security2019Top-tier venue
Probability Model Transforming Encoders Against Encoding Attacks
Haibo Cheng, Zhixiong Zheng, Wenting Li, Ping Wang, Chao-Hsien Chu
Abstract
Honey encryption (HE) is a novel encryption scheme for resisting brute-force attacks even using low-entropy keys (e.g., passwords). HE introduces a distribution transforming encoder (DTE) to yield plausible-looking decoy messages for incorrect keys. Several HE applications were proposed for specific messages with specially designed probability model transforming encoders (PMTEs), DTEs transformed from probability models which are used to characterize the intricate message distributions. We propose attacks against three typical PMTE schemes. Using a simple machine learning algorithm, we propose a distribution difference attack against genomic data PMTEs, achieving 76.54%-100.00% accuracy in distinguishing real data from decoy one. We then propose a new type of attackencoding attacks-against two password vault PMTEs, achieving 98.56%-99.52% accuracy. Different from distribution difference attacks, encoding attacks do not require any knowledge (statistics) about the real message distribution. We also introduce a generic conceptual probability modelgenerative probability model (GPM)-to formalize probability models and design a generic method for transforming an arbitrary GPM to a PMTE. We prove that our PMTEs are information-theoretically indistinguishable from the corresponding GPMs. Accordingly, they can resist encoding attacks. For our PMTEs transformed from existing password vault models, encoding attacks cannot achieve more than 52.56% accuracy, which is slightly better than the randomly guessing attack (50% accuracy).
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f5501ce3-471e-457b-a67f-d4607e5b4ad0Cited by top-tier papers3
- Incrementally Updateable Honey Password VaultsHaibo Cheng, Wenting Li, Ping Wang, Chao-Hsien Chu et al.USENIX Security 2021 · 15 citations
- A Security Analysis of Honey VaultsFei Duan, Ding Wang, Chunfu JiaS&P 2024 · 3 citations
- Practically Secure Honey Password Vaults: New Design and New Evaluation against Online GuessingHaibo Cheng, Fugeng Huang, Jiahong Yang, Wenting Li et al.USENIX Security 2025
Builds on10
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
- Who Are You? A Statistical Approach to Measuring User AuthenticityDavid Freeman, Sakshi Jain, Markus Dürmuth, Battista Biggio et al.NDSS 2016 · 151 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
- On the Accuracy of Password Strength MetersMaximilian Golla, Markus DürmuthCCS 2018 · 100 citations
Related papers
- On the Security of Cracking-Resistant Password VaultsMaximilian Golla, Benedict Beuscher, Markus DürmuthCCS 2016 · 54 citations
- How to Design Secure Honey Vault SchemesZhenduo Hou, Tingwei Fan, Fei Duan, Ding WangCCS 2025
- How to Attack and Generate HoneywordsDing Wang, Yunkai Zou, Qiying Dong, Yuanming Song et al.S&P 2022 · 45 citations
- The Impact of Exposed Passwords on Honeyword EfficacyZonghao Huang, Lujo Bauer, Michael K. ReiterUSENIX Security 2024 · 7 citations
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan et al.NDSS 2018 · 1,102 citations
