Abstract
A password guesser often uses wordlists (e.g. lists of previously leaked passwords, dictionaries of words in different languages, and lists of the most common passwords) to guess unknown passwords. The attacker needs to make a decision about what guesses to make and in what order. In an online guessing environment this is particularly important as they may be locked out after a certain number of wrong guesses. In this paper, we employ a multi-armed bandit model to show that an adaptive strategy can actively learn characteristics of the passwords it is guessing, and can leverage this information to dynamically weight the most appropriate wordlist. We also show that this can be used to identify the nationality of the users in a password set, and that guessing can be improved by guessing using passwords chosen by other users of the same nationality.
Author supplied keywords
Cite
CITATION STYLE
Murray, H., & Malone, D. (2022). Choosing Wordlists for Password Guessing: An Adaptive Multi-armed Bandit Approach. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 13291 LNCS, pp. 393–413). Springer Science and Business Media Deutschland GmbH. https://doi.org/10.1007/978-3-031-08147-7_27
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.