Targeted Online Password Guessing

密码 计算机科学 密码破解 计算机安全 密码强度 S/键 密码策略 击键记录 钥匙(锁) 互联网隐私 一次性密码 万维网
作者
Ding Wang,Zijian Zhang,Ping Wang,Jeff Yan,Xinyi Huang
标识
DOI:10.1145/2976749.2978339
摘要

While trawling online/offline password guessing has been intensively studied, only a few studies have examined targeted online guessing, where an attacker guesses a specific victim's password for a service, by exploiting the victim's personal information such as one sister password leaked from her another account and some personally identifiable information (PII). A key challenge for targeted online guessing is to choose the most effective password candidates, while the number of guess attempts allowed by a server's lockout or throttling mechanisms is typically very small. We propose TarGuess, a framework that systematically characterizes typical targeted guessing scenarios with seven sound mathematical models, each of which is based on varied kinds of data available to an attacker. These models allow us to design novel and efficient guessing algorithms. Extensive experiments on 10 large real-world password datasets show the effectiveness of TarGuess. Particularly, TarGuess I~IV capture the four most representative scenarios and within 100 guesses: (1) TarGuess-I outperforms its foremost counterpart by 142% against security-savvy users and by 46% against normal users; (2) TarGuess-II outperforms its foremost counterpart by 169% on security-savvy users and by 72% against normal users; and (3) Both TarGuess-III and IV gain success rates over 73% against normal users and over 32% against security-savvy users. TarGuess-III and IV, for the first time, address the issue of cross-site online guessing when given the victim's one sister password and some PII.
最长约 10秒,即可获得该文献文件

科研通智能强力驱动
Strongly Powered by AbleSci AI
更新
大幅提高文件上传限制,最高150M (2024-4-1)

科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
拼搏问薇完成签到 ,获得积分10
1秒前
curtisness应助白苏采纳,获得10
2秒前
2秒前
hihao发布了新的文献求助10
2秒前
有川洋一完成签到 ,获得积分10
3秒前
3秒前
ddd发布了新的文献求助10
3秒前
我是老大应助Tomice采纳,获得10
6秒前
奋斗人雄完成签到,获得积分10
7秒前
7秒前
能干的麦片完成签到 ,获得积分10
8秒前
852应助米六采纳,获得10
8秒前
旺仔完成签到,获得积分10
9秒前
思源应助活力寒梅采纳,获得10
9秒前
羊青丝完成签到,获得积分10
10秒前
充电宝应助123采纳,获得10
10秒前
千空完成签到,获得积分10
10秒前
103x完成签到 ,获得积分10
10秒前
11秒前
哭泣剑封完成签到,获得积分10
11秒前
852应助cen采纳,获得10
11秒前
Layli完成签到,获得积分10
12秒前
wangbq完成签到 ,获得积分10
13秒前
tb168tb完成签到,获得积分10
13秒前
13秒前
爆米花应助嘟嘟采纳,获得10
13秒前
15秒前
zho完成签到,获得积分0
17秒前
stop here完成签到,获得积分10
17秒前
苏格拉底的嘲笑完成签到,获得积分10
18秒前
十六完成签到,获得积分20
18秒前
研友_X84KrZ完成签到 ,获得积分10
18秒前
jonghuang发布了新的文献求助10
19秒前
21秒前
QYW发布了新的文献求助10
22秒前
SciGPT应助尘南浔采纳,获得10
24秒前
24秒前
曾建发布了新的文献求助10
25秒前
Fancy发布了新的文献求助50
25秒前
执行正义完成签到,获得积分10
25秒前
高分求助中
Sustainability in Tides Chemistry 2800
The Young builders of New china : the visit of the delegation of the WFDY to the Chinese People's Republic 1000
Rechtsphilosophie 1000
Bayesian Models of Cognition:Reverse Engineering the Mind 888
Handbook of Qualitative Cross-Cultural Research Methods 600
Very-high-order BVD Schemes Using β-variable THINC Method 568
Chen Hansheng: China’s Last Romantic Revolutionary 500
热门求助领域 (近24小时)
化学 医学 生物 材料科学 工程类 有机化学 生物化学 物理 内科学 纳米技术 计算机科学 化学工程 复合材料 基因 遗传学 催化作用 物理化学 免疫学 量子力学 细胞生物学
热门帖子
关注 科研通微信公众号,转发送积分 3137260
求助须知:如何正确求助?哪些是违规求助? 2788392
关于积分的说明 7785921
捐赠科研通 2444458
什么是DOI,文献DOI怎么找? 1299916
科研通“疑难数据库(出版商)”最低求助积分说明 625650
版权声明 601023