论文标题

密码猜测的调查

A Survey on Password Guessing

论文作者

Tran, Lam, Nguyen, Thuc, Seo, Changho, Kim, Hyunil, Choi, Deokjai

论文摘要

到目前为止,文本密码已成为用户身份验证的最流行方法,并且在可预见的将来不可能完全替换。密码身份验证提供了几种理想的属性(例如,低成本,高度可用,易于实施,可重复使用)。但是,它遭受了一个关键的安全问题,主要是由于无法记住复杂的人类弦。用户倾向于选择易于记录的密码,这些密码在关键空间中不均匀分布。因此,用户选择的密码容易猜测攻击。为了鼓励和支持用户使用强密码,有必要模拟自动密码猜测方法,以确定密码的强度并确定弱密码。文献中已经提出了大量密码猜测模型。但是,很少关注提供系统调查的任务,该调查是审查最新方法,识别差距并避免重复研究所必需的。由此激励,我们对1979年至2022年文献中提出的所有密码猜测研究进行了全面调查。我们提出了一张通用的方法学图,以介绍现有方法的概述。然后,我们详细解释了每种代表性方法。总结了用于评估密码猜测模型的实验程序和可用数据集,并比较了代表性研究的报告。最后,讨论了当前的局限性和开放问题。我们认为,这项调查对对密码安全感兴趣的专家和新移民都有帮助

Text password has served as the most popular method for user authentication so far, and is not likely to be totally replaced in foreseeable future. Password authentication offers several desirable properties (e.g., low-cost, highly available, easy-to-implement, reusable). However, it suffers from a critical security issue mainly caused by the inability to memorize complicated strings of humans. Users tend to choose easy-to-remember passwords which are not uniformly distributed in the key space. Thus, user-selected passwords are susceptible to guessing attacks. In order to encourage and support users to use strong passwords, it is necessary to simulate automated password guessing methods to determine the passwords' strength and identify weak passwords. A large number of password guessing models have been proposed in the literature. However, little attention was paid to the task of providing a systematic survey which is necessary to review the state-of-the-art approaches, identify gaps, and avoid duplicate studies. Motivated by that, we conduct a comprehensive survey on all password guessing studies presented in the literature from 1979 to 2022. We propose a generic methodology map to present an overview of existing methods. Then, we explain each representative approach in detail. The experimental procedures and available datasets used to evaluate password guessing models are summarized, and the reported performances of representative studies are compared. Finally, the current limitations and the open problems as future research directions are discussed. We believe that this survey is helpful to both experts and newcomers who are interested in password security

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源