DocumentCode :
2331036
Title :
Password Strength: An Empirical Analysis
Author :
Dell´Amico, Matteo ; Michiardi, Pietro ; Roudier, Yves
Author_Institution :
Eurecom, Sophia Antipolis, France
fYear :
2010
fDate :
14-19 March 2010
Firstpage :
1
Lastpage :
9
Abstract :
It is a well known fact that user-chosen passwords are somewhat predictable: by using tools such as dictionaries or probabilistic models, attackers and password recovery tools can drastically reduce the number of attempts needed to guess a password. Quite surprisingly, however, existing literature does not provide a satisfying answer to the following question: given a number of guesses, what is the probability that a state-of-the-art attacker will be able to break a password? To answer the former question, we compare and evaluate the effectiveness of currently known attacks using various datasets of known passwords. We find that a "diminishing returns" principle applies: in the absence of an enforced password strength policy, weak passwords are common; on the other hand, as the attack goes on, the probability that a guess will succeed decreases by orders of magnitude. Even extremely powerful attackers won\´t be able to guess a substantial percentage of the passwords. The result of this work will help in evaluating the security of authentication means based on user- chosen passwords, and our methodology for estimating password strength can be used as a basis for creating more effective proactive password checkers for users and security auditing tools for administrators.
Keywords :
estimation theory; probability; security of data; attackers; authentication; datasets; dictionaries; empirical analysis; password recovery; password strength estimation; probabilistic models; security auditing; Authentication; Best practices; Communications Society; Costs; Dictionaries; Internet; Length measurement; Predictive models; Resilience; Security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
INFOCOM, 2010 Proceedings IEEE
Conference_Location :
San Diego, CA
ISSN :
0743-166X
Print_ISBN :
978-1-4244-5836-3
Type :
conf
DOI :
10.1109/INFCOM.2010.5461951
Filename :
5461951
Link To Document :
بازگشت