Bernoulli Honeywords
Ke Coby Wang, Michael K. Reiter
摘要
Decoy passwords, or"honeywords,"planted in a credential database can alert a site to its breach if ever submitted in a login attempt. To be effective, some honeywords must appear at least as likely to be user-chosen passwords as the real ones, and honeywords must be very difficult to guess without having breached the database, to prevent false breach alarms. These goals have proved elusive, however, for heuristic honeyword generation algorithms. In this paper we explore an alternative strategy in which the defender treats honeyword selection as a Bernoulli process in which each possible password (except the user-chosen one) is selected as a honeyword independently with some fixed probability. We show how Bernoulli honeywords can be integrated into two existing system designs for leveraging honeywords: one based on a honeychecker that stores the secret index of the user-chosen password in the list of account passwords, and another that does not leverage secret state at all. We show that Bernoulli honeywords enable analytic derivation of false breach-detection probabilities irrespective of what information the attacker gathers about the sites' users; that their true and false breach-detection probabilities demonstrate compelling efficacy; and that Bernoulli honeywords can even enable performance improvements in modern honeyword system designs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- The Impact of Exposed Passwords on Honeyword EfficacyZonghao Huang, Lujo Bauer, Michael K. ReiterUSENIX Security 2024 · 被引用 7 次
- Detecting Compromise of Passkey Storage on the CloudMazharul Islam, Sunpreet S. Arora, Rahul Chatterjee, Ke Coby WangUSENIX Security 2025
它引用的顶会 Paper11
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan 等NDSS 2018 · 被引用 1,102 次
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett 等CCS 2017 · 被引用 248 次
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib 等CCS 2017 · 被引用 168 次
- On the Accuracy of Password Strength MetersMaximilian Golla, Markus DürmuthCCS 2018 · 被引用 100 次
相关 Paper
- How to Attack and Generate HoneywordsDing Wang, Yunkai Zou, Qiying Dong, Yuanming Song 等S&P 2022 · 被引用 45 次
- Using Amnesia to Detect Credential Database BreachesKe Coby Wang, Michael K. ReiterUSENIX Security 2021 · 被引用 18 次
- On the Security of Cracking-Resistant Password VaultsMaximilian Golla, Benedict Beuscher, Markus DürmuthCCS 2016 · 被引用 54 次
- Probability Model Transforming Encoders Against Encoding AttacksHaibo Cheng, Zhixiong Zheng, Wenting Li, Ping Wang 等USENIX Security 2019 · 被引用 12 次
- How to Design Secure Honey Vault SchemesZhenduo Hou, Tingwei Fan, Fei Duan, Ding WangCCS 2025
