Reasoning Analytically about Password-Cracking Software
Enze Liu, Amanda Nakanishi, Maximilian Golla, David Cash, Blase Ur
摘要
A rich literature has presented efficient techniques for estimating password strength by modeling password-cracking algorithms. Unfortunately, these previous techniques only apply to probabilistic password models, which real attackers seldom use. In this paper, we introduce techniques to reason analytically and efficiently about transformation-based password cracking in software tools like John the Ripper and Hashcat. We define two new operations, rule inversion and guess counting, with which we analyze these tools without needing to enumerate guesses. We implement these techniques and find orders-of-magnitude reductions in the time it takes to estimate password strength. We also present four applications showing how our techniques enable increased scientific rigor in optimizing these attacks' configurations. In particular, we show how our techniques can leverage revealed password data to improve orderings of transformation rules and to identify rules and words potentially missing from an attack configuration. Our work thus introduces some of the first principled mechanisms for reasoning scientifically about the types of password-guessing attacks that occur in practice.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper12
- Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic DictionariesDario Pasquini, Marco Cianfriglia, Giuseppe Ateniese, Massimo BernaschiUSENIX Security 2021 · 被引用 41 次
- Chunk-Level Password Guessing: Towards Modeling Refined Password Composition RepresentationsMing Xu, Chuanwang Wang, Jitao Yu, Junjie Zhang 等CCS 2021 · 被引用 32 次
- Universal Neural-Cracking-Machines: Self-Configurable Password Models from Auxiliary DataDario Pasquini, Giuseppe Ateniese, Carmela TroncosoS&P 2024 · 被引用 14 次
- An Investigation of Identity-Account Inconsistency in Single Sign-OnGuannan Liu, Xing Gao, Haining WangWWW 2021 · 被引用 9 次
- Success Rates Doubled with Only One Character: Mask Password GuessingYunkai Zou, Ding Wang, Fei DuanNDSS 2026 · 被引用 1 次
它引用的顶会 Paper4
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri 等USENIX Security 2016 · 被引用 331 次
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 被引用 243 次
- On the Accuracy of Password Strength MetersMaximilian Golla, Markus DürmuthCCS 2018 · 被引用 100 次
相关 Paper
- Improving Real-world Password Guessing Attacks via Bi-directional TransformersMing Xu, Jitao Yu, Xinyi Zhang, Chuanwang Wang 等USENIX Security 2023
- Password Guessing Using Random ForestDing Wang, Yunkai Zou, Zijian Zhang, Kedong XiuUSENIX Security 2023
- Towards a Rigorous Statistical Analysis of Empirical Password DatasetsJeremiah Blocki, Peiyuan LiuS&P 2023
- MoPE: A Mixture of Password Experts for Improving Password GuessingMingjian Duan, Ming Xu, Shenghao Zhang, Weili HanS&P 2026
- Targeted Password Guessing Using k-Nearest NeighborsZhen Li, Ding WangNDSS 2026 · 被引用 2 次
