Saved in:
Bibliographic Details
Main Authors: Johnson, Saul, Ferreira, João, Mendes, Alexandra, Cordry, Julien
Format: Preprint
Published: 2020
Subjects:
Online Access:https://arxiv.org/abs/2003.05846
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866914714845446144
author Johnson, Saul
Ferreira, João
Mendes, Alexandra
Cordry, Julien
author_facet Johnson, Saul
Ferreira, João
Mendes, Alexandra
Cordry, Julien
contents Large-scale password data breaches are becoming increasingly commonplace, which has enabled researchers to produce a substantial body of password security research utilising real-world password datasets, which often contain numbers of records in the tens or even hundreds of millions. While much study has been conducted on how password composition policies (sets of rules that a user must abide by when creating a password) influence the distribution of user-chosen passwords on a system, much less research has been done on inferring the password composition policy that a given set of user-chosen passwords was created under. In this paper, we state the problem with the naive approach to this challenge, and suggest a simple approach that produces more reliable results. We also present pol-infer, a tool that implements this approach, and demonstrates its use in inferring password composition policies.
format Preprint
id arxiv_https___arxiv_org_abs_2003_05846
institution arXiv
publishDate 2020
record_format arxiv
spellingShingle Lost in Disclosure: On The Inference of Password Composition Policies
Johnson, Saul
Ferreira, João
Mendes, Alexandra
Cordry, Julien
Cryptography and Security
Large-scale password data breaches are becoming increasingly commonplace, which has enabled researchers to produce a substantial body of password security research utilising real-world password datasets, which often contain numbers of records in the tens or even hundreds of millions. While much study has been conducted on how password composition policies (sets of rules that a user must abide by when creating a password) influence the distribution of user-chosen passwords on a system, much less research has been done on inferring the password composition policy that a given set of user-chosen passwords was created under. In this paper, we state the problem with the naive approach to this challenge, and suggest a simple approach that produces more reliable results. We also present pol-infer, a tool that implements this approach, and demonstrates its use in inferring password composition policies.
title Lost in Disclosure: On The Inference of Password Composition Policies
topic Cryptography and Security
url https://arxiv.org/abs/2003.05846