How to Attack and Generate Honeywords
Ding Wang, Yunkai Zou, Qiying Dong, Yuanming Song, Xinyi Huang
摘要
Honeywords are decoy passwords associated with each user account to timely detect password leakage. The key issue lies in how to generate honeywords that are hard to be differentiated from real passwords. This security mechanism was first introduced by Juels and Rivest at CCS’13, and has been covered by hundreds of media and adopted in dozens of research domains. Existing research deals with honeywords primarily in an ad hoc manner, and it is challenging to develop a secure honeyword-generation method and well evaluate (attack) it. In this work, we tackle this problem in a principled approach. We first propose four theoretic models for characterizing the attacker ’s best distinguishing strategies, with each model based on a different combination of information available to (e.g., public datasets, the victim’s personal information and registration order). These theories guide us to design effective experiments with real-world password datasets to evaluate the goodness (flatness) of a given honeyword-generation method.Armed with the four best attacking theories, we develop the corresponding honeyword-generation method for each type of attackers, by using various representative probabilistic password guessing models. Through a series of exploratory investigations, we show the use of these password models is not straightforward, but requires creative and significant efforts. Both empirical experiments and user-study results demonstrate that our methods significantly outperform prior art. Besides, we manage to resolve several previously unexplored challenges that arise in the practical deployment of a honeyword method. We believe this work pushes the honeyword research towards statistical rigor.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Universal Neural-Cracking-Machines: Self-Configurable Password Models from Auxiliary DataDario Pasquini, Giuseppe Ateniese, Carmela TroncosoS&P 2024 · 被引用 14 次
- The Impact of Exposed Passwords on Honeyword EfficacyZonghao Huang, Lujo Bauer, Michael K. ReiterUSENIX Security 2024 · 被引用 7 次
- A Security Analysis of Honey VaultsFei Duan, Ding Wang, Chunfu JiaS&P 2024 · 被引用 3 次
- Success Rates Doubled with Only One Character: Mask Password GuessingYunkai Zou, Ding Wang, Fei DuanNDSS 2026 · 被引用 1 次
- No Single Silver Bullet: Measuring the Accuracy of Password Strength MetersDing Wang, Xuan Shan, Qiying Dong, Yaosheng Shen 等USENIX Security 2023
它引用的顶会 Paper15
- A Security Analysis of HoneywordsDing Wang, Haibo Cheng, Ping Wang, Jeff Yan 等NDSS 2018 · 被引用 1,102 次
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri 等USENIX Security 2016 · 被引用 331 次
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 被引用 243 次
- Hackers vs. Testers: A Comparison of Software Vulnerability Discovery ProcessesDaniel Votipka, Rock Stevens, Elissa M. Redmiles, Jeremy Hu 等S&P 2018 · 被引用 151 次
相关 Paper
- Bernoulli HoneywordsKe Coby Wang, Michael K. ReiterNDSS 2024
- Using Amnesia to Detect Credential Database BreachesKe Coby Wang, Michael K. ReiterUSENIX Security 2021 · 被引用 18 次
- How to Design Secure Honey Vault SchemesZhenduo Hou, Tingwei Fan, Fei Duan, Ding WangCCS 2025
- On the Security of Cracking-Resistant Password VaultsMaximilian Golla, Benedict Beuscher, Markus DürmuthCCS 2016 · 被引用 54 次
- Practically Secure Honey Password Vaults: New Design and New Evaluation against Online GuessingHaibo Cheng, Fugeng Huang, Jiahong Yang, Wenting Li 等USENIX Security 2025
