conference-paper Open access

Choosing Wordlists for Password Guessing: An Adaptive Multi-armed Bandit Approach

  • Lecture notes in computer science
  • Springer Science+Business Media
Research footprint

At a glance

Citations
0
References
18
Comments
0
Paper overview

Abstract

Abstract A password guesser often uses wordlists (e.g. lists of previously leaked passwords, dictionaries of words in different languages, and lists of the most common passwords) to guess unknown passwords. The attacker needs to make a decision about what guesses to make and in what order. In an online guessing environment this is particularly important as they may be locked out after a certain number of wrong guesses. In this paper, we employ a multi-armed bandit model to show that an adaptive strategy can actively learn characteristics of the passwords it is guessing, and can leverage this information to dynamically weight the most appropriate wordlist. We also show that this can be used to identify the nationality of the users in a password set, and that guessing can be improved by guessing using passwords chosen by other users of the same nationality.

Record transparency

Publication details

DOI
10.1007/978-3-031-08147-7_27
OpenAlex
W4285182648
Document type
conference-paper
Language
EN
Source
Lecture notes in computer science
Last metadata update
Community

Comments

Log in to join the discussion.

  1. No comments yet. Start the discussion.