The Community for Technology Leaders
Green Image
Issue No. 05 - Sept.-Oct. (2017 vol. 14)
ISSN: 1545-5971
pp: 550-564
Shouling Ji , College of Computer Science and Technology, Zhejiang University, Hangzhou, Zhejiang, China
Shukun Yang , School of Electrical and Computer Engineering, Georgia Institute of Technology, Atlanta, GA
Xin Hu , IBM T. J. Watson Research Center
Weili Han , Software SchoolFudan University
Zhigong Li , Software SchoolFudan University
Raheem Beyah , School of Electrical and Computer Engineering, Georgia Institute of Technology, Atlanta, GA
ABSTRACT
In this paper, we conduct a large-scale study on the crackability, correlation, and security of $_${\sim}145$_$ million real world passwords, which were leaked from several popular Internet services and applications. To the best of our knowledge, this is the largest empirical study that has been conducted. Specifically, we first evaluate the crackability of $_${\sim}145$_$ million real world passwords against 6+ state-of-the-art password cracking algorithms in multiple scenarios. Second, we examine the effectiveness and soundness of popular commercial password strength meters (e.g., Google, QQ) and the security impacts of username/email leakage on passwords. Finally, we discuss the implications of our results, analysis, and findings, which are expected to help both password users and system administrators to gain a deeper understanding of the vulnerability of real passwords against state-of-the-art password cracking algorithms, as well as to shed light on future password security research topics.
INDEX TERMS
Markov processes, Dictionaries, Training, Security, Training data, Electronic mail, Games
CITATION

S. Ji, S. Yang, X. Hu, W. Han, Z. Li and R. Beyah, "Zero-Sum Password Cracking Game: A Large-Scale Empirical Study on the Crackability, Correlation, and Security of Passwords," in IEEE Transactions on Dependable and Secure Computing, vol. 14, no. 5, pp. 550-564, 2017.
doi:10.1109/TDSC.2015.2481884
443 ms
(Ver 3.3 (11022016))