Title
Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms
Abstract
Text-based passwords remain the dominant authentication method in computer systems, despite significant advancement in attackers' capabilities to perform password cracking. In response to this threat, password composition policies have grown increasingly complex. However, there is insufficient research defining metrics to characterize password strength and using them to evaluate password-composition policies. In this paper, we analyze 12,000 passwords collected under seven composition policies via an online study. We develop an efficient distributed method for calculating how effectively several heuristic password-guessing algorithms guess passwords. Leveraging this method, we investigate (a) the resistance of passwords created under different conditions to guessing, (b) the performance of guessing algorithms under different training sets, (c) the relationship between passwords explicitly created under a given composition policy and other passwords that happen to meet the same requirements, and (d) the relationship between guess ability, as measured with password-cracking algorithms, and entropy estimates. Our findings advance understanding of both password-composition policies and metrics for quantifying password security.
Year
DOI
Venue
2012
10.1109/SP.2012.38
IEEE Symposium on Security and Privacy
Keywords
Field
DocType
dominant authentication method,password strength,password-cracking algorithms,different condition,composition policy,text-based password,password-composition policy,different training set,password composition policy,guess ability,password security,measuring password strength,computer network security,measurement,authentication,passwords,computer access control,metrics,password cracking,policies,resistance,dictionaries,entropy,algorithms,entropy estimation,attack,authorisation
Computer access control,Internet privacy,Password cracking,Password strength,Computer security,Computer science,Network security,Algorithm,One-time password,Password policy,Password,Cognitive password
Conference
ISSN
ISBN
Citations 
1081-6011
978-0-7695-4681-0
143
PageRank 
References 
Authors
4.74
31
9
Search Limit
100143
Name
Order
Citations
PageRank
Patrick Gage Kelley1167979.74
Saranga Komanduri2109541.21
Michelle L. Mazurek3105957.67
Richard Shay4107343.90
Timothy Vidas571538.49
Lujo Bauer62460120.71
Nicolas Christin72133126.02
Lorrie Faith Cranor86767515.80
Julio Lopez91434.74