作者
Ding Wang, Zijian Zhang, Ping Wang, Jeff Yan, Xinyi Huang
发表日期
2016/7/23
期刊
ACM CCS 2016
页码范围
1-13
出版商
ACM
简介
While trawling online/offline password guessing has been intensively studied, only a few studies have examined targeted online guessing, where an attacker guesses a specific victim's password for a service, by exploiting the victim's personal information such as one sister password leaked from her another account and some personally identifiable information (PII). A key challenge for targeted online guessing is to choose the most effective password candidates, while the number of guess attempts allowed by a server's lockout or throttling mechanisms is typically very small. We propose TarGuess, a framework that systematically characterizes typical targeted guessing scenarios with seven sound mathematical models, each of which is based on varied kinds of data available to an attacker. These models allow us to design novel and efficient guessing algorithms. Extensive experiments on 10 large real-world …
引用总数
20162017201820192020202120222023202453347616563695114
学术搜索中的文章
D Wang, Z Zhang, P Wang, J Yan, X Huang - Proceedings of the 2016 ACM SIGSAC conference on …, 2016