The Experts below are selected from a list of 1110 Experts worldwide ranked by ideXlab platform

Massimo Bernaschi - One of the best experts on this subject based on the ideXlab platform.

  • interpretable probabilistic Password Strength meters via deep learning
    2020
    Co-Authors: Dario Pasquini, Giuseppe Ateniese, Massimo Bernaschi
    Abstract:

    Probabilistic Password Strength meters have been proved to be the most accurate tools to measure Password Strength. Unfortunately, by construction, they are limited to solely produce an opaque security estimation that fails to fully support the user during the Password composition. In the present work, we move the first steps towards cracking the intelligibility barrier of this compelling class of meters. We show that probabilistic Password meters inherently own the capability to describe the latent relation between Password Strength and Password structure. In our approach, the security contribution of each character composing a Password is disentangled and used to provide explicit fine-grained feedback for the user. Furthermore, unlike existing heuristic constructions, our method is free from any human bias, and, more importantly, its feedback has a clear probabilistic interpretation.

  • interpretable probabilistic Password Strength meters via deep learning
    2020
    Co-Authors: Dario Pasquini, Giuseppe Ateniese, Massimo Bernaschi
    Abstract:

    Probabilistic Password Strength meters have been proved to be the most accurate tools to measure Password Strength. Unfortunately, by construction, they are limited to solely produce an opaque security estimation that fails to fully support the user during the Password composition. In the present work, we move the first steps towards cracking the intelligibility barrier of this compelling class of meters. We show that probabilistic Password meters inherently own the capability of describing the latent relation occurring between Password Strength and Password structure. In our approach, the security contribution of each character composing a Password is disentangled and used to provide explicit fine-grained feedback for the user. Furthermore, unlike existing heuristic constructions, our method is free from any human bias, and, more importantly, its feedback has a clear probabilistic interpretation. In our contribution: (1) we formulate the theoretical foundations of interpretable probabilistic Password Strength meters; (2) we describe how they can be implemented via an efficient and lightweight deep learning framework suitable for client-side operability.

  • reducing bias in modeling real world Password Strength via deep learning and dynamic dictionaries
    2020
    Co-Authors: Dario Pasquini, Giuseppe Ateniese, Marco Cianfriglia, Massimo Bernaschi
    Abstract:

    Password security hinges on an in-depth understanding of the techniques adopted by attackers. Unfortunately, real-world adversaries resort to pragmatic guessing strategies such as dictionary attacks that are inherently difficult to model in Password security studies. In order to be representative of the actual threat, dictionary attacks must be thoughtfully configured and tuned. However, this process requires a domain-knowledge and expertise that cannot be easily replicated. The consequence of inaccurately calibrating dictionary attacks is the unreliability of Password security analyses, impaired by a severe measurement bias. In the present work, we introduce a new generation of dictionary attacks that is consistently more resilient to inadequate configurations. Requiring no supervision or domain-knowledge, this technique automatically approximates the advanced guessing strategies adopted by real-world attackers. To achieve this: (1) We use deep neural networks to model the proficiency of adversaries in building attack configurations. (2) Then, we introduce dynamic guessing strategies within dictionary attacks. These mimic experts' ability to adapt their guessing strategies on the fly by incorporating knowledge on their targets. Our techniques enable more robust and sound Password Strength estimates within dictionary attacks, eventually reducing overestimation in modeling real-world threats in Password security. Code available: this https URL

Joseph Bonneau - One of the best experts on this subject based on the ideXlab platform.

  • statistical metrics for individual Password Strength
    2012
    Co-Authors: Joseph Bonneau
    Abstract:

    We propose several possible metrics for measuring the Strength of an individual Password or any other secret drawn from a known, skewed distribution. In contrast to previous ad hoc approaches which rely on textual properties of Passwords, we consider the problem without any knowledge of Password structure. This enables rating the Strength of a Password given a large sample distribution without assuming anything about Password semantics. We compare the results of our generic metrics against those of the NIST metrics and other previous "entropy-based" metrics for a large Password dataset, which suggest over-fitting in previous metrics.

  • statistical metrics for individual Password Strength transcript of discussion
    2012
    Co-Authors: Joseph Bonneau
    Abstract:

    I'm not proposing any protocols here, I'm talking about Passwords, which is what I've spent the last year or so doing now. An interesting problem, which came up in my thesis, is how to tell how strong an individual Password is. There's a growing body of publications on how to assess the Strength of a big pile of Passwords. So if a bunch of Passwords leak from a new website there are some measures that I've developed, and some things other people have worked on, to try and compare this new body of Passwords to all of the Passwords at a different website. But the world of analysing a single Password is still in the dark ages I would say. Obviously the difference is that with a group of Passwords you can start to do statistics, and you can look at how many Passwords are repeated within that set, whereas if you just have one Password you have to reason about what set it came from.

Dario Pasquini - One of the best experts on this subject based on the ideXlab platform.

  • interpretable probabilistic Password Strength meters via deep learning
    2020
    Co-Authors: Dario Pasquini, Giuseppe Ateniese, Massimo Bernaschi
    Abstract:

    Probabilistic Password Strength meters have been proved to be the most accurate tools to measure Password Strength. Unfortunately, by construction, they are limited to solely produce an opaque security estimation that fails to fully support the user during the Password composition. In the present work, we move the first steps towards cracking the intelligibility barrier of this compelling class of meters. We show that probabilistic Password meters inherently own the capability to describe the latent relation between Password Strength and Password structure. In our approach, the security contribution of each character composing a Password is disentangled and used to provide explicit fine-grained feedback for the user. Furthermore, unlike existing heuristic constructions, our method is free from any human bias, and, more importantly, its feedback has a clear probabilistic interpretation.

  • interpretable probabilistic Password Strength meters via deep learning
    2020
    Co-Authors: Dario Pasquini, Giuseppe Ateniese, Massimo Bernaschi
    Abstract:

    Probabilistic Password Strength meters have been proved to be the most accurate tools to measure Password Strength. Unfortunately, by construction, they are limited to solely produce an opaque security estimation that fails to fully support the user during the Password composition. In the present work, we move the first steps towards cracking the intelligibility barrier of this compelling class of meters. We show that probabilistic Password meters inherently own the capability of describing the latent relation occurring between Password Strength and Password structure. In our approach, the security contribution of each character composing a Password is disentangled and used to provide explicit fine-grained feedback for the user. Furthermore, unlike existing heuristic constructions, our method is free from any human bias, and, more importantly, its feedback has a clear probabilistic interpretation. In our contribution: (1) we formulate the theoretical foundations of interpretable probabilistic Password Strength meters; (2) we describe how they can be implemented via an efficient and lightweight deep learning framework suitable for client-side operability.

  • reducing bias in modeling real world Password Strength via deep learning and dynamic dictionaries
    2020
    Co-Authors: Dario Pasquini, Giuseppe Ateniese, Marco Cianfriglia, Massimo Bernaschi
    Abstract:

    Password security hinges on an in-depth understanding of the techniques adopted by attackers. Unfortunately, real-world adversaries resort to pragmatic guessing strategies such as dictionary attacks that are inherently difficult to model in Password security studies. In order to be representative of the actual threat, dictionary attacks must be thoughtfully configured and tuned. However, this process requires a domain-knowledge and expertise that cannot be easily replicated. The consequence of inaccurately calibrating dictionary attacks is the unreliability of Password security analyses, impaired by a severe measurement bias. In the present work, we introduce a new generation of dictionary attacks that is consistently more resilient to inadequate configurations. Requiring no supervision or domain-knowledge, this technique automatically approximates the advanced guessing strategies adopted by real-world attackers. To achieve this: (1) We use deep neural networks to model the proficiency of adversaries in building attack configurations. (2) Then, we introduce dynamic guessing strategies within dictionary attacks. These mimic experts' ability to adapt their guessing strategies on the fly by incorporating knowledge on their targets. Our techniques enable more robust and sound Password Strength estimates within dictionary attacks, eventually reducing overestimation in modeling real-world threats in Password security. Code available: this https URL

Lorrie Faith Cranor - One of the best experts on this subject based on the ideXlab platform.

  • Measuring Password Guessability for an Entire University (CMU-CyLab-13-013)
    2018
    Co-Authors: Michelle L Mazurek, Nicolas Christin, Timothy Vidas, Saranga Komanduri, Lorrie Faith Cranor, Ljudevit Bauer, Patrick Kelley, Richard Shay
    Abstract:

    Despite considerable research on Passwords, empirical studies of Password Strength have been limited by lack of access to plaintext Passwords, small data sets, and Password sets specifically collected for a research study or from low-value accounts. Properties of Passwords used for high-value accounts thus remain poorly understood. We fill this gap by studying the single-sign-on Passwords used by over 25,000 faculty, staff, and students at a research university with a complex Password policy. Key aspects of our contributions rest on our (indirect) access to plaintext Passwords. We describe our data collection methodology, particularly the many precautions we took to minimize risks to users. We then analyze how guessable the collected Passwords would be during an offline attack by subjecting them to a state-of-the-art Password cracking algorithm. We discover significant correlations between a number of demographic and behavioral factors and Password Strength. For example, we find that users associated with the computer science school make Passwords more than 1.8 times as strong as those of users associated with the business school. In addition, we find that stronger Passwords are correlated with a higher rate of errors entering them. We also compare the guessability and other characteristics of the Passwords we analyzed to sets previously collected in controlled experiments or leaked from low-value accounts. We find more consistent similarities between the university Passwords and Passwords collected for research studies under similar composition policies than we do between the university Passwords and subsets of Passwords leaked from low-value accounts that happen to comply with the same policies.

  • fast lean and accurate modeling Password guessability using neural networks
    2016
    Co-Authors: William Melicher, Sean M. Segreti, Lujo Bauer, Nicolas Christin, Saranga Komanduri, Lorrie Faith Cranor
    Abstract:

    Human-chosen text Passwords, today's dominant form of authentication, are vulnerable to guessing attacks. Unfortunately, existing approaches for evaluating Password Strength by modeling adversarial Password guessing are either inaccurate or orders of magnitude too large and too slow for real-time, client-side Password checking. We propose using artificial neural networks to model text Passwords' resistance to guessing attacks and explore how different architectures and training methods impact neural networks' guessing effectiveness. We show that neural networks can often guess Passwords more effectively than state-of-the-art approaches, such as probabilistic context-free grammars and Markov models. We also show that our neural networks can be highly compressed-to as little as hundreds of kilobytes-without substantially worsening guessing effectiveness. Building on these results, we implement in JavaScript the first principled client-side model of Password guessing, which analyzes a Password's resistance to a guessing attack of arbitrary duration with sub-second latency. Together, our contributions enable more accurate and practical Password checking than was previously possible.

  • Designing Password Policies for Strength and Usability
    2016
    Co-Authors: Richard Shay, Adam L. Durity, Sean M. Segreti, Blase Ur, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Saranga Komanduri, Lorrie Faith Cranor
    Abstract:

    Password-composition policies are the result of service providers becoming increasingly concerned about the security of online accounts. These policies restrict the space of user-created Passwords to preclude easily guessed Passwords and thus make Passwords more difficult for attackers to guess. However, many users struggle to create and recall their Passwords under strict Password-composition policies, for example, ones that require Passwords to have at least eight characters with multiple character classes and a dictionary check. Recent research showed that a promising alternative was to focus policy requirements on Password length instead of on complexity. In this work, we examine 15 Password policies, many focusing on length requirements. In doing so, we contribute the first thorough examination of policies requiring longer Passwords. We conducted two online studies with over 20,000 participants, and collected both usability and Password-Strength data. Our findings indicate that Password Strength and Password usability are not necessarily inversely correlated: policies that lead to stronger Passwords do not always reduce usability. We identify policies that are both more usable and more secure than commonly used policies that emphasize complexity rather than length requirements. We also provide practical recommendations for service providers who want their users to have strong yet usable Passwords.

  • USENIX Association 24th USENIX Security Symposium 463 Measuring Real-World Accuracies and Biases in Modeling Password Guessability
    2016
    Co-Authors: Sean M. Segreti, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Saranga Kom, Darya Kurilova, William Melicher, Richard Shay
    Abstract:

    Parameterized Password guessability—how many guesses a particular cracking algorithm with particular training data would take to guess a Password—has become a common metric of Password security. Unlike statistical metrics, it aims to model real-world attackers and to provide per-Password Strength estimates. We investigate how cracking approaches often used by researchers compare to real-world cracking by profes-sionals, as well as how the choice of approach biases research conclusions. We find that semi-automated cracking by profession-als outperforms popular fully automated approaches, but can be approximated by combining multiple such ap-proaches. These approaches are only effective, however, with careful configuration and tuning; in commonly used default configurations, they underestimate the real-world guessability of Passwords. We find that analyses of large Password sets are often robust to the algorithm used for guessing as long as it is configured effectively. However, cracking algorithms differ systematically in their effec-tiveness guessing Passwords with certain common fea-tures (e.g., character substitutions). This has important implications for analyzing the security of specific pass-word characteristics or of individual Passwords (e.g., in a Password meter or security audit). Our results highlight the danger of relying only on a single cracking algorithm as a measure of Password Strength and constitute the first scientific evidence that automated guessing can often ap-proximate guessing by professionals.

  • Measuring real-world accuracies and biases in modeling Password guessability
    2015
    Co-Authors: Sean M. Segreti, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Saranga Kom, Darya Kurilova, William Melicher, Richard Shay
    Abstract:

    Parameterized Password guessability—how many guesses a particular cracking algorithm with particular training data would take to guess a Password—has become a common metric of Password security. Unlike statistical metrics, it aims to model real-world attackers and to provide per-Password Strength estimates. We investigate how cracking approaches often used by researchers compare to real-world cracking by profes-sionals, as well as how the choice of approach biases research conclusions. We find that semi-automated cracking by profession-als outperforms popular fully automated approaches, but can be approximated by combining multiple such ap-proaches. These approaches are only effective, however, with careful configuration and tuning; in commonly used default configurations, they underestimate the real-world guessability of Passwords. We find that analyses of large Password sets are often robust to the algorithm used for guessing as long as it is configured effectively. However, cracking algorithms differ systematically in their effec-tiveness guessing Passwords with certain common fea-tures (e.g., character substitutions). This has important implications for analyzing the security of specific pass-word characteristics or of individual Passwords (e.g., in a Password meter or security audit). Our results highlight the danger of relying only on a single cracking algorithm as a measure of Password Strength and constitute the first scientific evidence that automated guessing can often ap-proximate guessing by professionals.

Richard Shay - One of the best experts on this subject based on the ideXlab platform.

  • Measuring Password Guessability for an Entire University (CMU-CyLab-13-013)
    2018
    Co-Authors: Michelle L Mazurek, Nicolas Christin, Timothy Vidas, Saranga Komanduri, Lorrie Faith Cranor, Ljudevit Bauer, Patrick Kelley, Richard Shay
    Abstract:

    Despite considerable research on Passwords, empirical studies of Password Strength have been limited by lack of access to plaintext Passwords, small data sets, and Password sets specifically collected for a research study or from low-value accounts. Properties of Passwords used for high-value accounts thus remain poorly understood. We fill this gap by studying the single-sign-on Passwords used by over 25,000 faculty, staff, and students at a research university with a complex Password policy. Key aspects of our contributions rest on our (indirect) access to plaintext Passwords. We describe our data collection methodology, particularly the many precautions we took to minimize risks to users. We then analyze how guessable the collected Passwords would be during an offline attack by subjecting them to a state-of-the-art Password cracking algorithm. We discover significant correlations between a number of demographic and behavioral factors and Password Strength. For example, we find that users associated with the computer science school make Passwords more than 1.8 times as strong as those of users associated with the business school. In addition, we find that stronger Passwords are correlated with a higher rate of errors entering them. We also compare the guessability and other characteristics of the Passwords we analyzed to sets previously collected in controlled experiments or leaked from low-value accounts. We find more consistent similarities between the university Passwords and Passwords collected for research studies under similar composition policies than we do between the university Passwords and subsets of Passwords leaked from low-value accounts that happen to comply with the same policies.

  • Designing Password Policies for Strength and Usability
    2016
    Co-Authors: Richard Shay, Adam L. Durity, Sean M. Segreti, Blase Ur, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Saranga Komanduri, Lorrie Faith Cranor
    Abstract:

    Password-composition policies are the result of service providers becoming increasingly concerned about the security of online accounts. These policies restrict the space of user-created Passwords to preclude easily guessed Passwords and thus make Passwords more difficult for attackers to guess. However, many users struggle to create and recall their Passwords under strict Password-composition policies, for example, ones that require Passwords to have at least eight characters with multiple character classes and a dictionary check. Recent research showed that a promising alternative was to focus policy requirements on Password length instead of on complexity. In this work, we examine 15 Password policies, many focusing on length requirements. In doing so, we contribute the first thorough examination of policies requiring longer Passwords. We conducted two online studies with over 20,000 participants, and collected both usability and Password-Strength data. Our findings indicate that Password Strength and Password usability are not necessarily inversely correlated: policies that lead to stronger Passwords do not always reduce usability. We identify policies that are both more usable and more secure than commonly used policies that emphasize complexity rather than length requirements. We also provide practical recommendations for service providers who want their users to have strong yet usable Passwords.

  • USENIX Association 24th USENIX Security Symposium 463 Measuring Real-World Accuracies and Biases in Modeling Password Guessability
    2016
    Co-Authors: Sean M. Segreti, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Saranga Kom, Darya Kurilova, William Melicher, Richard Shay
    Abstract:

    Parameterized Password guessability—how many guesses a particular cracking algorithm with particular training data would take to guess a Password—has become a common metric of Password security. Unlike statistical metrics, it aims to model real-world attackers and to provide per-Password Strength estimates. We investigate how cracking approaches often used by researchers compare to real-world cracking by profes-sionals, as well as how the choice of approach biases research conclusions. We find that semi-automated cracking by profession-als outperforms popular fully automated approaches, but can be approximated by combining multiple such ap-proaches. These approaches are only effective, however, with careful configuration and tuning; in commonly used default configurations, they underestimate the real-world guessability of Passwords. We find that analyses of large Password sets are often robust to the algorithm used for guessing as long as it is configured effectively. However, cracking algorithms differ systematically in their effec-tiveness guessing Passwords with certain common fea-tures (e.g., character substitutions). This has important implications for analyzing the security of specific pass-word characteristics or of individual Passwords (e.g., in a Password meter or security audit). Our results highlight the danger of relying only on a single cracking algorithm as a measure of Password Strength and constitute the first scientific evidence that automated guessing can often ap-proximate guessing by professionals.

  • Measuring real-world accuracies and biases in modeling Password guessability
    2015
    Co-Authors: Sean M. Segreti, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Saranga Kom, Darya Kurilova, William Melicher, Richard Shay
    Abstract:

    Parameterized Password guessability—how many guesses a particular cracking algorithm with particular training data would take to guess a Password—has become a common metric of Password security. Unlike statistical metrics, it aims to model real-world attackers and to provide per-Password Strength estimates. We investigate how cracking approaches often used by researchers compare to real-world cracking by profes-sionals, as well as how the choice of approach biases research conclusions. We find that semi-automated cracking by profession-als outperforms popular fully automated approaches, but can be approximated by combining multiple such ap-proaches. These approaches are only effective, however, with careful configuration and tuning; in commonly used default configurations, they underestimate the real-world guessability of Passwords. We find that analyses of large Password sets are often robust to the algorithm used for guessing as long as it is configured effectively. However, cracking algorithms differ systematically in their effec-tiveness guessing Passwords with certain common fea-tures (e.g., character substitutions). This has important implications for analyzing the security of specific pass-word characteristics or of individual Passwords (e.g., in a Password meter or security audit). Our results highlight the danger of relying only on a single cracking algorithm as a measure of Password Strength and constitute the first scientific evidence that automated guessing can often ap-proximate guessing by professionals.

  • guess again and again and again measuring Password Strength by simulating Password cracking algorithms
    2012
    Co-Authors: Patrick Gage Kelley, Michelle L Mazurek, Lujo Bauer, Nicolas Christin, Richard Shay, Timothy Vidas, Saranga Komanduri, Lorrie Faith Cranor, Julio Lopez
    Abstract:

    Text-based Passwords remain the dominant authentication method in computer systems, despite significant advancement in attackers' capabilities to perform Password cracking. In response to this threat, Password composition policies have grown increasingly complex. However, there is insufficient research defining metrics to characterize Password Strength and using them to evaluate Password-composition policies. In this paper, we analyze 12,000 Passwords collected under seven composition policies via an online study. We develop an efficient distributed method for calculating how effectively several heuristic Password-guessing algorithms guess Passwords. Leveraging this method, we investigate (a) the resistance of Passwords created under different conditions to guessing, (b) the performance of guessing algorithms under different training sets, (c) the relationship between Passwords explicitly created under a given composition policy and other Passwords that happen to meet the same requirements, and (d) the relationship between guess ability, as measured with Password-cracking algorithms, and entropy estimates. Our findings advance understanding of both Password-composition policies and metrics for quantifying Password security.