Practically Secure Honey Password Vaults: New Design and New Evaluation against Online Guessing
Haibo Cheng, Fugeng Huang, Jiahong Yang, Wenting Li, Ping Wang
摘要
Password vaults are used to manage multiple account passwords, encrypted with a master password. However, ciphertext stored on synchronization servers is vulnerable to leakage and offline guessing attacks, potentially compromising all accounts. Honey password vaults address this by generating decoy vaults for incorrect master passwords, making offline guessing infeasible and requiring online verification.
Existing studies on honey vaults rely on a small dataset of only 276 vaults for model training and security evaluation, limiting their conclusions. More importantly, existing evaluations focus solely on the distinguishability between real and decoy vaults, overlooking practical security: How many accounts could be cracked via online guessing?
In this paper, we construct a large dataset of millions of vaults by aggregating numerous leaked password datasets. With the dataset, we employ advanced machine learning techniques for both decoy generation and identification. We show that various text classification algorithms, especially pre-trained models, significantly outperform existing attacks with distinguishing accuracy of 95.79%-83.75%. Further, we introduce a Transformer model that generates more plausible decoy vaults, no attacks achieve accuracy more than 64.35%.
We further assess the practical security of honey vaults against online guessing. Our new model achieves the best performance, only 0.51 accounts is cracked on average with 1,000 online attempts. By applying two simple measures, we enhance the scheme to a practical level: 1) using honey accounts for leakage detection, and 2) avoiding the encryption of passwords for websites with unlimited login attempts. These improvements reduce the cracked number to 0.11. We also offer new insights, such as that even a poor model can achieve notable practical security by using our measures.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah 等NeurIPS 2020 · 被引用 64,255 次
- Deberta: decoding-Enhanced Bert with Disentangled AttentionPengcheng He, Xiaodong Liu, Jianfeng Gao, Weizhu ChenICLR 2021 · 被引用 3,729 次
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- Improving Password Guessing via Representation LearningDario Pasquini, Ankit Gangwal, Giuseppe Ateniese, Massimo Bernaschi 等S&P 2021 · 被引用 101 次
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 被引用 100 次
相关 Paper
- Incrementally Updateable Honey Password VaultsHaibo Cheng, Wenting Li, Ping Wang, Chao-Hsien Chu 等USENIX Security 2021 · 被引用 15 次
- On the Security of Cracking-Resistant Password VaultsMaximilian Golla, Benedict Beuscher, Markus DürmuthCCS 2016 · 被引用 54 次
- A Security Analysis of Honey VaultsFei Duan, Ding Wang, Chunfu JiaS&P 2024 · 被引用 3 次
- How to Design Secure Honey Vault SchemesZhenduo Hou, Tingwei Fan, Fei Duan, Ding WangCCS 2025
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan 等NDSS 2018 · 被引用 1,102 次
