Visible to the public An Online Password Guessing Method Based on Big Data

TitleAn Online Password Guessing Method Based on Big Data
Publication TypeConference Paper
Year of Publication2019
AuthorsLi, Zhiyong, Li, Tao, Zhu, Fangdong
Conference NameProceedings of the 2019 3rd International Conference on Intelligent Systems, Metaheuristics & Swarm Intelligence
PublisherAssociation for Computing Machinery
Conference LocationMale, Maldives
ISBN Number978-1-4503-7211-4
Keywordscomposability, compositionality, password guessing attack, password security, proactive password check, pubcrawl, swarm intelligence
AbstractPassword authentication is the most widely used authentication method in information systems. The traditional proactive password detection method is generally implemented by counting password length, character class number and computing password information entropy to improve password security. However, passwords that pass proactive password detection do not represent that they are secure. In this paper, based on the research of the characteristics of password distribution under big data, we propose an online password guessing method, which collects a dataset of guessing passwords composed of weak passwords, high frequency passwords and personal information related passwords. It is used to guess the 13k password dataset leaked in China's largest ticketing website, China Railways 12306 website. The experimental results show that even if our guess object has passed the strict proactive password detection, we can construct a guessing password dataset contain only 100 passwords, and effectively guess 4.84% of the passwords.
URLhttps://doi.org/10.1145/3325773.3325779
DOI10.1145/3325773.3325779
Citation Keyli_online_2019