The Experts below are selected from a list of 18831 Experts worldwide ranked by ideXlab platform

Massimo Bernaschi - One of the best experts on this subject based on the ideXlab platform.

  • reducing bias in modeling real world Password strength via deep learning and dynamic dictionaries
    USENIX Security Symposium, 2020
    Co-Authors: Dario Pasquini, Giuseppe Ateniese, Marco Cianfriglia, Massimo Bernaschi
    Abstract:

    Password Security hinges on an in-depth understanding of the techniques adopted by attackers. Unfortunately, real-world adversaries resort to pragmatic guessing strategies such as dictionary attacks that are inherently difficult to model in Password Security studies. In order to be representative of the actual threat, dictionary attacks must be thoughtfully configured and tuned. However, this process requires a domain-knowledge and expertise that cannot be easily replicated. The consequence of inaccurately calibrating dictionary attacks is the unreliability of Password Security analyses, impaired by a severe measurement bias. In the present work, we introduce a new generation of dictionary attacks that is consistently more resilient to inadequate configurations. Requiring no supervision or domain-knowledge, this technique automatically approximates the advanced guessing strategies adopted by real-world attackers. To achieve this: (1) We use deep neural networks to model the proficiency of adversaries in building attack configurations. (2) Then, we introduce dynamic guessing strategies within dictionary attacks. These mimic experts' ability to adapt their guessing strategies on the fly by incorporating knowledge on their targets. Our techniques enable more robust and sound Password strength estimates within dictionary attacks, eventually reducing overestimation in modeling real-world threats in Password Security. Code available: this https URL

Julio Lopez - One of the best experts on this subject based on the ideXlab platform.

  • guess again and again and again measuring Password strength by simulating Password cracking algorithms
    IEEE Symposium on Security and Privacy, 2012
    Co-Authors: Patrick Gage Kelley, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Richard Shay, Timothy Vidas, Saranga Komanduri, Lorrie Faith Cranor, Julio Lopez
    Abstract:

    Text-based Passwords remain the dominant authentication method in computer systems, despite significant advancement in attackers' capabilities to perform Password cracking. In response to this threat, Password composition policies have grown increasingly complex. However, there is insufficient research defining metrics to characterize Password strength and using them to evaluate Password-composition policies. In this paper, we analyze 12,000 Passwords collected under seven composition policies via an online study. We develop an efficient distributed method for calculating how effectively several heuristic Password-guessing algorithms guess Passwords. Leveraging this method, we investigate (a) the resistance of Passwords created under different conditions to guessing, (b) the performance of guessing algorithms under different training sets, (c) the relationship between Passwords explicitly created under a given composition policy and other Passwords that happen to meet the same requirements, and (d) the relationship between guess ability, as measured with Password-cracking algorithms, and entropy estimates. Our findings advance understanding of both Password-composition policies and metrics for quantifying Password Security.

  • guess again and again and again measuring Password strength by simulating Password cracking algorithms cmu cylab 11 008
    2011
    Co-Authors: Patrick Gage Kelley, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Richard Shay, Timothy Vidas, Saranga Komanduri, Lorrie Faith Cranor, Julio Lopez
    Abstract:

    Text-based Passwords remain the dominant authentication method in computer systems, despite significant advancement in attackers’ capabilities to perform Password cracking. In response to this threat, Password composition policies have grown increasingly complex. However, there is insufficient research defining metrics to characterize Password strength and evaluating Password-composition policies using these metrics. In this paper, we describe an analysis of 12,000 Passwords collected under seven composition policies via an online study. We develop an efficient distributed method for calculating how effectively several heuristic Password-guessing algorithms guess Passwords. Leveraging this method, we investigate (a) the resistance of Passwords created under different conditions to Password guessing; (b) the performance of guessing algorithms under different training sets; (c) the relationship between Passwords explicitly created under a given composition policy and other Passwords that happen to meet the same requirements; and (d) the relationship between guessability, as measured with Password-cracking algorithms, and entropy estimates. We believe our findings advance understanding of both Password-composition policies and metrics for quantifying Password Security.

Raheem Beyah - One of the best experts on this subject based on the ideXlab platform.

  • dppg a dynamic Password policy generation system
    IEEE Transactions on Information Forensics and Security, 2018
    Co-Authors: Shukun Yang, Raheem Beyah
    Abstract:

    To keep Password users from creating simple and common Passwords, major websites and applications provide a Password-strength measure, namely a Password checker. While critical requirements for a Password checker to be stringent have prevailed in the study of Password Security, we show that regardless of the stringency, such static checkers can leak information and actually help the adversary enhance the performance of their attacks. To address this weakness, we propose and devise the Dynamic Password Policy Generator , namely DPPG , to be an effective and usable alternative to the existing Password strength checker. DPPG aims to enforce an evenly-distributed Password space and generate dynamic policies for users to create Passwords that are diverse and that contribute to the overall Security of the Password database. Since DPPG is modular and can function with different underlying metrics for policy generation, we further introduce a diversity-based Password Security metric that evaluates the Security of a Password database in terms of Password space and distribution. The metric is useful as a countermeasure to well-crafted offline cracking algorithms and theoretically illustrates why DPPG works well.

  • zero sum Password cracking game a large scale empirical study on the crackability correlation and Security of Passwords
    IEEE Transactions on Dependable and Secure Computing, 2017
    Co-Authors: Shouling Ji, Shukun Yang, Zhigong Li, Xin Hu, Raheem Beyah
    Abstract:

    In this paper, we conduct a large-scale study on the crackability, correlation, and Security of ${\sim}145$ million real world Passwords, which were leaked from several popular Internet services and applications. To the best of our knowledge, this is the largest empirical study that has been conducted. Specifically, we first evaluate the crackability of ${\sim}145$ million real world Passwords against 6+ state-of-the-art Password cracking algorithms in multiple scenarios. Second, we examine the effectiveness and soundness of popular commercial Password strength meters (e.g., Google, QQ) and the Security impacts of username/email leakage on Passwords. Finally, we discuss the implications of our results, analysis, and findings, which are expected to help both Password users and system administrators to gain a deeper understanding of the vulnerability of real Passwords against state-of-the-art Password cracking algorithms, as well as to shed light on future Password Security research topics.

Anthony Vance - One of the best experts on this subject based on the ideXlab platform.

  • can individuals neutralization techniques be overcome a field experiment on Password policy
    Computers & Security, 2020
    Co-Authors: Mikko T Siponen, Petri Puhakainen, Anthony Vance
    Abstract:

    Abstract Individuals’ lack of adherence to Password Security policy is a persistent problem for organizations. This problem is especially worrisome because Passwords remain the primary authentication mechanism for information systems, and the number of Passwords has been increasing. For these reasons, determining methods to improve individuals’ adherence to Password-Security policies constitutes an important issue for organizations. Extant research has shown that individuals use neutralization techniques, i.e., types of rationalizations, to disregard organizational information-Security policies. What has not been determined from extant information Security research is whether these neutralizations can be changed through educational training interventions. We argue that training based on principles of cognitive dissonance theory is a promising method for reducing individuals’ use of neutralization techniques. We contribute by showing empirically that training based on cognitive dissonance theory can reduce the use of neutralization techniques when such training is designed to counter such techniques. Using a quasi-experimental design at an organization, individuals received training on neutralization techniques in the context of Password Security. Using a quasi-experimental design, we found that individuals who received our training treatment exhibited substantially less intent to use neutralization techniques and were significantly more likely to use secure Passwords. Additionally, a follow-up measurement three weeks after the training session showed that the experimental treatment retained its effectiveness, i.e., the experimental group exhibited substantially less intent to use neutralization techniques and a greater likelihood of using strong Passwords in the future. Additionally, intent was significantly greater in the experimental group. Implications for practice and future research are discussed.

  • enhancing Password Security through interactive fear appeals a web based field experiment
    Hawaii International Conference on System Sciences, 2013
    Co-Authors: Anthony Vance, David Eargle, Kirk Ouimet, Detmar W Straub
    Abstract:

    Passwords remain the dominant authentication mechanism for information Security. Unfortunately, research has shown that most Passwords are highly insecure. Given the risks of using weak Passwords, there is a need to effectively motivate users to select strong Passwords. In this study we examine the influence of interactivity, as well as static and interactive fear appeals, on motivating users to increase the strength of their Passwords. We developed a field experiment involving the account registration process of a website in use in which we observed the strength of Passwords chosen by users. Data were collected from 354 users in 65 countries. We found that while the interactive Password strength meter and static fear appeal treatments were not effective, the interactive fear appeal treatment resulted in significantly stronger Passwords. Our findings suggest that interactive fear appeals are a promising means of encouraging a range of secure behaviors in end users.

Dario Pasquini - One of the best experts on this subject based on the ideXlab platform.

  • reducing bias in modeling real world Password strength via deep learning and dynamic dictionaries
    USENIX Security Symposium, 2020
    Co-Authors: Dario Pasquini, Giuseppe Ateniese, Marco Cianfriglia, Massimo Bernaschi
    Abstract:

    Password Security hinges on an in-depth understanding of the techniques adopted by attackers. Unfortunately, real-world adversaries resort to pragmatic guessing strategies such as dictionary attacks that are inherently difficult to model in Password Security studies. In order to be representative of the actual threat, dictionary attacks must be thoughtfully configured and tuned. However, this process requires a domain-knowledge and expertise that cannot be easily replicated. The consequence of inaccurately calibrating dictionary attacks is the unreliability of Password Security analyses, impaired by a severe measurement bias. In the present work, we introduce a new generation of dictionary attacks that is consistently more resilient to inadequate configurations. Requiring no supervision or domain-knowledge, this technique automatically approximates the advanced guessing strategies adopted by real-world attackers. To achieve this: (1) We use deep neural networks to model the proficiency of adversaries in building attack configurations. (2) Then, we introduce dynamic guessing strategies within dictionary attacks. These mimic experts' ability to adapt their guessing strategies on the fly by incorporating knowledge on their targets. Our techniques enable more robust and sound Password strength estimates within dictionary attacks, eventually reducing overestimation in modeling real-world threats in Password Security. Code available: this https URL