A Security Analysis of Honeywords

计算机科学 计算机安全
作者
Ding Wang,Haibo Cheng,Píng Wang,Jeff Yan,Xinyi Huang
标识
DOI:10.14722/ndss.2018.23142
摘要

Honeywords are decoy passwords associated with each user account, and they contribute a promising approach to detecting password leakage.This approach was first proposed by Juels and Rivest at CCS'13, and has been covered by hundreds of medias and also adopted in various research domains.The idea of honeywords looks deceptively simple, but it is a deep and sophisticated challenge to automatically generate honeywords that are hard to differentiate from real passwords.In Juels-Rivest's work, four main honeyword-generation methods are suggested but only justified by heuristic security arguments.In this work, we for the first time develop a series of practical experiments using 10 large-scale datasets, a total of 104 million real-world passwords, to quantitatively evaluate the security that these four methods can provide.Our results reveal that they all fail to provide the expected security: real passwords can be distinguished with a success rate of 29.29%∼32.62%by our basic trawling-guessing attacker, but not the expected 5%, with just one guess (when each user account is associated with 19 honeywords as recommended).This figure reaches 34.21%∼49.02%under the advanced trawling-guessing attackers who make use of various state-of-the-art probabilistic password models.We further evaluate the security of Juels-Rivest's methods under a targeted-guessing attacker who can exploit the victim' personal information, and the results are even more alarming: 56.81%∼67.98%.Overall, our work resolves three open problems in honeyword research, as defined by Juels and Rivest.

科研通智能强力驱动
Strongly Powered by AbleSci AI
科研通是完全免费的文献互助平台,具备全网最快的应助速度,最高的求助完成率。 对每一个文献求助,科研通都将尽心尽力,给求助人一个满意的交代。
实时播报
牛俊生发布了新的文献求助10
1秒前
颜哈哈发布了新的文献求助10
2秒前
Sumeru发布了新的文献求助10
2秒前
3秒前
5秒前
Akim应助福桃采纳,获得10
6秒前
6秒前
7秒前
科研通AI2S应助NiuNiu4采纳,获得10
7秒前
车访枫发布了新的文献求助10
8秒前
夜未央完成签到,获得积分20
9秒前
9秒前
wxh16403发布了新的文献求助10
10秒前
小小雪完成签到 ,获得积分10
10秒前
10秒前
充电宝应助Kismet采纳,获得10
12秒前
糖糖发布了新的文献求助10
13秒前
y'y'y发布了新的文献求助10
13秒前
安仔完成签到,获得积分10
13秒前
zoro完成签到,获得积分10
13秒前
我刚上小学完成签到,获得积分10
14秒前
14秒前
YANG发布了新的文献求助10
14秒前
lm完成签到 ,获得积分10
15秒前
wxh16403完成签到,获得积分10
15秒前
Seiswan完成签到,获得积分10
15秒前
曦颜完成签到 ,获得积分10
16秒前
Beyond完成签到,获得积分0
16秒前
科研通AI5应助xxhui采纳,获得10
17秒前
杨阳完成签到,获得积分20
17秒前
18秒前
牛俊生完成签到 ,获得积分20
18秒前
ym完成签到,获得积分10
18秒前
李爱国应助carly采纳,获得10
19秒前
朱大妹完成签到,获得积分10
20秒前
Owen应助LiuShenglan采纳,获得10
20秒前
momo发布了新的文献求助10
21秒前
汉堡包应助杨阳采纳,获得30
22秒前
Kismet完成签到,获得积分10
22秒前
24秒前
高分求助中
Production Logging: Theoretical and Interpretive Elements 2700
Neuromuscular and Electrodiagnostic Medicine Board Review 1000
こんなに痛いのにどうして「なんでもない」と医者にいわれてしまうのでしょうか 510
The First Nuclear Era: The Life and Times of a Technological Fixer 500
ALUMINUM STANDARDS AND DATA 500
岡本唐貴自伝的回想画集 500
Distinct Aggregation Behaviors and Rheological Responses of Two Terminally Functionalized Polyisoprenes with Different Quadruple Hydrogen Bonding Motifs 450
热门求助领域 (近24小时)
化学 材料科学 医学 生物 工程类 有机化学 物理 生物化学 纳米技术 计算机科学 化学工程 内科学 复合材料 物理化学 电极 遗传学 量子力学 基因 冶金 催化作用
热门帖子
关注 科研通微信公众号,转发送积分 3668189
求助须知:如何正确求助?哪些是违规求助? 3226562
关于积分的说明 9770261
捐赠科研通 2936503
什么是DOI,文献DOI怎么找? 1608620
邀请新用户注册赠送积分活动 759734
科研通“疑难数据库(出版商)”最低求助积分说明 735521