Sign in to use this feature.

Years

Between: -

Subjects

remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline
remove_circle_outline

Journals

Article Types

Countries / Regions

Search Results (5)

Search Parameters:
Keywords = targeted password guessing

Order results
Result details
Results per page
Select all
Export citation of selected articles as:
17 pages, 583 KB  
Article
Cross-Domain Feature Enhancement-Based Password Guessing Method for Small Samples
by Cheng Liu, Junrong Li, Xiheng Liu, Bo Li, Mengsu Hou, Wei Yu, Yujun Li and Wenjun Liu
Entropy 2025, 27(7), 752; https://doi.org/10.3390/e27070752 - 15 Jul 2025
Viewed by 1398
Abstract
As a crucial component of account protection system evaluation and intrusion detection, the advancement of password guessing technology encounters challenges due to its reliance on password data. In password guessing research, there is a conflict between the traditional models’ need for large training [...] Read more.
As a crucial component of account protection system evaluation and intrusion detection, the advancement of password guessing technology encounters challenges due to its reliance on password data. In password guessing research, there is a conflict between the traditional models’ need for large training samples and the limitations on accessing password data imposed by privacy protection regulations. Consequently, security researchers often struggle with the issue of having a very limited password set from which to guess. This paper introduces a small-sample password guessing technique that enhances cross-domain features. It analyzes the password set using probabilistic context-free grammar (PCFG) to create a list of password structure probabilities and a dictionary of password fragment probabilities, which are then used to generate a password set structure vector. The method calculates the cosine similarity between the small-sample password set B from the target area and publicly leaked password sets Ai using the structure vector, identifying the set Amax with the highest similarity. This set is then utilized as a training set, where the features of the small-sample password set are enhanced by modifying the structure vectors of the training set. The enhanced training set is subsequently employed for PCFG password generation. The paper uses hit rate as the evaluation metric, and Experiment I reveals that the similarity between B and Ai can be reliably measured when the size of B exceeds 150. Experiment II confirms the hypothesis that a higher similarity between Ai and B leads to a greater hit rate of Ai on the test set of B, with potential improvements of up to 32% compared to training with B alone. Experiment III demonstrates that after enhancing the features of Amax, the hit rate for the small-sample password set can increase by as much as 10.52% compared to previous results. This method offers a viable solution for small-sample password guessing without requiring prior knowledge. Full article
(This article belongs to the Section Information Theory, Probability and Statistics)
►▼ Show Figures

Figure 1

25 pages, 850 KB  
Article
Similarities: The Key Factors Influencing Cross-Site Password Guessing Performance
by Zhijie Xie, Fan Shi, Min Zhang, Zhihong Rao, Yuxuan Zhou and Xiaoyu Ji
Electronics 2025, 14(5), 945; https://doi.org/10.3390/electronics14050945 - 27 Feb 2025
Cited by 2 | Viewed by 2427
Abstract
Password guessing is a crucial research direction in password security, considering vulnerabilities like password reuse and data breaches. While research has extensively explored intra-site password guessing, the complexities of cross-site attacks, where attackers use leaked data from one site to target another, remain [...] Read more.
Password guessing is a crucial research direction in password security, considering vulnerabilities like password reuse and data breaches. While research has extensively explored intra-site password guessing, the complexities of cross-site attacks, where attackers use leaked data from one site to target another, remain less understood. This study investigates the impact of dataset feature similarity on cross-site password guessing performance, revealing that dataset differences significantly influence guessing success more than model variations. By analyzing eight password datasets and four guessing methods, we identified eight key features affecting guessing success, including general data features like length distribution and specific semantic features like PCFG grammar. Our research reveals that syntactic and statistical patterns in passwords, particularly PCFG features, are most effective for cross-site password guessing due to their strong generalization across datasets. The Spearman correlation coefficient of 0.754 between PCFG feature similarity and guessing success rate indicates a significant positive correlation, unlike the minimal impact of length distribution features (0.284). These findings highlight the importance of focusing on robust semantic features like PCFG for improving password guessing techniques and security strategies. Additionally, the study underscores the importance of dataset selection for attackers and suggests that defenders can enhance security by mitigating feature similarity with commonly leaked data. Full article
(This article belongs to the Section Computer Science & Engineering)
►▼ Show Figures

Figure 1

17 pages, 1887 KB  
Article
A Secret Key Classification Framework of Symmetric Encryption Algorithm Based on Deep Transfer Learning
by Xiaotong Cui, Hongxin Zhang, Xing Fang, Yuanzhen Wang, Danzhi Wang, Fan Fan and Lei Shu
Appl. Sci. 2023, 13(21), 12025; https://doi.org/10.3390/app132112025 - 3 Nov 2023
Cited by 5 | Viewed by 3043
Abstract
The leakage signals, including electromagnetic, energy, time, and temperature, generated during the operation of password devices contain highly correlated key information, which leads to security vulnerabilities. In traditional encryption algorithms, the length of the key greatly affects the upper limit of its security [...] Read more.
The leakage signals, including electromagnetic, energy, time, and temperature, generated during the operation of password devices contain highly correlated key information, which leads to security vulnerabilities. In traditional encryption algorithms, the length of the key greatly affects the upper limit of its security against cracking. Regarding side-channel attacks on long-key algorithms, traditional template attack methods characterize the energy traces using multivariate Gaussian distribution during the template construction phase. The exhaustive key-guessing process is expected to consume a significant amount of time and computational resources. Therefore, to analyze the effectiveness of obtaining key values from the side information of password devices, we propose an innovative attack method based on a divide-and-conquer logical structure, targeting semi-bytes. We construct a collection of key classification submodules with symmetric correlations. By integrating a differential network model for byte-block sets and an end-to-end direct attack method, we form a holistic symmetric decision framework and propose a key classification structure based on deep transfer learning. This structure consists of three main parts: side information data acquisition, analysis of key-value effectiveness, and determination of attack positions. It employs multiple parallel symmetric subnetworks, effectively improving attack efficiency and reducing the key enumeration range. Experimental results show that the optimal attack accuracy of the network model can reach 91%, with an average attack accuracy of 78%. It overcomes overfitting issues under small sample dataset conditions. Full article
(This article belongs to the Special Issue New Advance in Electronic Information Security)
►▼ Show Figures

Figure 1

28 pages, 3532 KB  
Review
A Systematic Review on Password Guessing Tasks
by Wei Yu, Qingsong Yin, Hao Yin, Wei Xiao, Tao Chang, Liangliang He, Lulin Ni and Qingbing Ji
Entropy 2023, 25(9), 1303; https://doi.org/10.3390/e25091303 - 7 Sep 2023
Cited by 19 | Viewed by 10216
Abstract
Recently, many password guessing algorithms have been proposed, seriously threatening cyber security. In this paper, we systematically review over thirty methods for password guessing published between 2016 and 2023. First, we introduce a taxonomy for classifying the existing methods into trawling guessing and [...] Read more.
Recently, many password guessing algorithms have been proposed, seriously threatening cyber security. In this paper, we systematically review over thirty methods for password guessing published between 2016 and 2023. First, we introduce a taxonomy for classifying the existing methods into trawling guessing and targeted guessing. Second, we present an extensive benchmark dataset that can assist researchers and practitioners in successive works. Third, we conduct a bibliometric analysis to present trends in this field and cross-citation between reviewed papers. Further, we discuss the open challenges of password guessing in terms of diverse application scenarios, guessing efficiency, and the combination of traditional and deep learning methods. Finally, this review presents future research directions to guide successive research and development of password guessing. Full article
(This article belongs to the Section Entropy Reviews)
►▼ Show Figures

Figure 1

20 pages, 3039 KB  
Article
Study on Massive-Scale Slow-Hash Recovery Using Unified Probabilistic Context-Free Grammar and Symmetrical Collaborative Prioritization with Parallel Machines
by Tianjun Wu, Yuexiang Yang, Chi Wang and Rui Wang
Symmetry 2019, 11(4), 450; https://doi.org/10.3390/sym11040450 - 1 Apr 2019
Cited by 3 | Viewed by 4846
Abstract
Slow-hash algorithms are proposed to defend against traditional offline password recovery by making the hash function very slow to compute. In this paper, we study the problem of slow-hash recovery on a large scale. We attack the problem by proposing a novel concurrent [...] Read more.
Slow-hash algorithms are proposed to defend against traditional offline password recovery by making the hash function very slow to compute. In this paper, we study the problem of slow-hash recovery on a large scale. We attack the problem by proposing a novel concurrent model that guesses the target password hash by leveraging known passwords from a largest-ever password corpus. Previously proposed password-reused learning models are specifically designed for targeted online guessing for a single hash and thus cannot be efficiently parallelized for massive-scale offline recovery, which is demanded by modern hash-cracking tasks. In particular, because the size of a probabilistic context-free grammar (PCFG for short) model is non-trivial and keeping track of the next most probable password to guess across all global accounts is difficult, we choose clever data structures and only expand transformations as needed to make the attack computationally tractable. Our adoption of max-min heap, which globally ranks weak accounts for both expanding and guessing according to unified PCFGs and allows for concurrent global ranking, significantly increases the hashes can be recovered within limited time. For example, 59.1% accounts in one of our target password list can be found in our source corpus, allowing our solution to recover 20.1% accounts within one week at an average speed of 7200 non-identical passwords cracked per hour, compared to previous solutions such as oclHashcat (using default configuration), which cracks at an average speed of 28 and needs months to recover the same number of accounts with equal computing resources (thus are infeasible for a real-world attacker who would maximize the gain against the cracking cost). This implies an underestimated threat to slow-hash protected password dumps. Our method provides organizations with a better model of offline attackers and helps them better decide the hashing costs of slow-hash algorithms and detect potential vulnerable credentials before hackers do. Full article
►▼ Show Figures

Figure 1

Back to TopTop