Choosing Wordlists for Password Guessing: An Adaptive Multi-armed Bandit Approach
At a glance
- Citations
- 0
- References
- 18
- Comments
- 0
Abstract
Abstract A password guesser often uses wordlists (e.g. lists of previously leaked passwords, dictionaries of words in different languages, and lists of the most common passwords) to guess unknown passwords. The attacker needs to make a decision about what guesses to make and in what order. In an online guessing environment this is particularly important as they may be locked out after a certain number of wrong guesses. In this paper, we employ a multi-armed bandit model to show that an adaptive strategy can actively learn characteristics of the passwords it is guessing, and can leverage this information to dynamically weight the most appropriate wordlist. We also show that this can be used to identify the nationality of the users in a password set, and that guessing can be improved by guessing using passwords chosen by other users of the same nationality.
Publication details
- DOI
- 10.1007/978-3-031-08147-7_27
- OpenAlex
- W4285182648
- Document type
- conference-paper
- Language
- EN
- Source
- Lecture notes in computer science
- Last metadata update
Comments
Log in to join the discussion.