DocumentCode
243237
Title
Efficient dictionary for salted password analysis
Author
Vishwakarma, Deepak ; Madhavan, C. E. Veni
Author_Institution
Comput. Sci. & Autom., Indian Inst. Sci., Bangalore, India
fYear
2014
fDate
6-7 Jan. 2014
Firstpage
1
Lastpage
6
Abstract
User authentication is essential for accessing computing resources, network resources, email accounts, online portals etc. To authenticate a user, system stores user credentials (user id and password pair) in system. It has been an interested field problem to discover user password from a system and similarly protecting them against any such possible attack. In this work we show that passwords are still vulnerable to hash chain based and efficient dictionary attacks. Human generated passwords use some identifiable patterns. We have analysed a sample of 19 million passwords, of different lengths, available on-line and studied the distribution of the symbols in the password strings. We show that the distribution of symbols in user passwords is affected by the native language of the user. From symbol distributions we can build smart and efficient dictionaries, which are smaller in size and their coverage of plausible passwords from Key-space is large. These smart dictionaries make dictionary based attacks practical.
Keywords
dictionaries; message authentication; efficient dictionary attacks; native language; salted password analysis; smart dictionaries; user authentication; user credentials; Dictionaries; authentication; hash chain; hash function; password cracking; salted passwords; security; smart dictionary;
fLanguage
English
Publisher
ieee
Conference_Titel
Electronics, Computing and Communication Technologies (IEEE CONECCT), 2014 IEEE International Conference on
Conference_Location
Bangalore
Print_ISBN
978-1-4799-2318-2
Type
conf
DOI
10.1109/CONECCT.2014.6740293
Filename
6740293
Link To Document