中文
相关论文

相关论文: When AI Defeats Password Deception! A Deep Learnin…

200 篇论文

Honeywords are fictitious passwords inserted into databases in order to identify password breaches. The major difficulty is how to produce honeywords that are difficult to distinguish from real passwords. Although the generation of…

人工智能 · 计算机科学 2022-08-24 Fangyi Yu , Miguel Vargas Martin

Honeywords are decoy passwords that can be added to a credential database; if a login attempt uses a honeyword, this indicates that the site's credential database has been leaked. In this paper we explore the basic requirements for…

密码学与安全 · 计算机科学 2024-03-07 Zonghao Huang , Lujo Bauer , Michael K. Reiter

Honeyword is a representative "honey" technique that employs decoy objects to mislead adversaries and protect the real ones. To assess the security of a Honeyword system, two metrics--flatness and success-number--have been proposed and…

密码学与安全 · 计算机科学 2025-04-22 Pengcheng Su , Haibo Cheng , Wenting Li , Ping Wang

Decoy passwords, or "honeywords," planted in a credential database can alert a site to its breach if ever submitted in a login attempt. To be effective, some honeywords must appear at least as likely to be user-chosen passwords as the real…

密码学与安全 · 计算机科学 2023-11-22 Ke Coby Wang , Michael K. Reiter

State-of-the-art password guessing tools, such as HashCat and John the Ripper, enable users to check billions of passwords per second against password hashes. In addition to performing straightforward dictionary attacks, these tools can…

密码学与安全 · 计算机科学 2019-02-18 Briland Hitaj , Paolo Gasti , Giuseppe Ateniese , Fernando Perez-Cruz

Introduced by Juels and Rivest in 2013, Honeywords, which are decoy passwords stored alongside a real password, appear to be a proactive method to help detect password credentials misuse. However, despite over a decade of research, this…

密码学与安全 · 计算机科学 2025-10-28 Sudiksha Das , Ashish Kundu

The security of passwords is dependent on a thorough understanding of the strategies used by attackers. Unfortunately, real-world adversaries use pragmatic guessing tactics like dictionary attacks, which are difficult to simulate in…

密码学与安全 · 计算机科学 2022-12-13 Fangyi Yu

Using password based authentication technique, a system maintains the login credentials (username, password) of the users in a password file. Once the password file is compromised, an adversary obtains both the login credentials. With the…

密码学与安全 · 计算机科学 2017-05-31 Nilesh Chakraborty , Samrat Mondal

Password security hinges on an in-depth understanding of the techniques adopted by attackers. Unfortunately, real-world adversaries resort to pragmatic guessing strategies such as dictionary attacks that are inherently difficult to model in…

密码学与安全 · 计算机科学 2021-03-01 Dario Pasquini , Marco Cianfriglia , Giuseppe Ateniese , Massimo Bernaschi

Machine Learning is becoming a pivotal aspect of many systems today, offering newfound performance on classification and prediction tasks, but this rapid integration also comes with new unforeseen vulnerabilities. To harden these systems…

密码学与安全 · 计算机科学 2022-02-22 Ahmed Abdou , Ryan Sheatsley , Yohan Beugin , Tyler Shipp , Patrick McDaniel

Inverting the hash values by performing brute force computation is one of the latest security threats on password based authentication technique. New technologies are being developed for brute force computation and these increase the…

密码学与安全 · 计算机科学 2015-09-22 Nilesh Chakraborty , Samrat Mondal

Modern trend sees a lot usage of \textit{honeywords} (or fake password) for protecting the original passwords in the password file. However, the usage of \textit{honeywords} has strongly been criticized under the different security and…

密码学与安全 · 计算机科学 2017-08-07 Nilesh Chakraborty , Shreya Singh , Samrat Mondal

The security of passwords depends on a thorough understanding of the strategies used by attackers. Unfortunately, real-world adversaries use pragmatic guessing tactics like dictionary attacks, which are difficult to simulate in password…

密码学与安全 · 计算机科学 2022-08-16 Fangyi Yu , Miguel Vargas Martin

With the increasing prevalence of security incidents, the adoption of deception-based defense strategies has become pivotal in cyber security. This work addresses the challenge of scalability in designing honeytokens, a key component of…

The remarkable capabilities of Large Language Models (LLMs) in natural language understanding and generation have sparked interest in their potential for cybersecurity applications, including password guessing. In this study, we conduct an…

密码学与安全 · 计算机科学 2026-01-01 Mohammad Abdul Rehman , Syed Imad Ali Shah , Abbas Anwar , Noor Islam , Hamid Khan

Decoy passwords, or ``honeywords,'' alert a site to its breach if entered in a login attempt on that site. However, an attacker can identify a user-chosen password from among the decoys, without alerting the site to its breach, via…

密码学与安全 · 计算机科学 2026-05-14 Mridu Nanda , Michael K. Reiter

In this work, we investigate the effectiveness of deep-learning-based password guessing models for targeted attacks on human-chosen passwords. In recent years, service providers have increased the level of security of users'passwords. This…

密码学与安全 · 计算机科学 2023-06-19 Etienne Salimbeni , Nina Mainusch , Dario Pasquini

The rise in malicious usage of large language models, such as fake content creation and academic plagiarism, has motivated the development of approaches that identify AI-generated text, including those based on watermarking or outlier…

计算与语言 · 计算机科学 2023-10-19 Kalpesh Krishna , Yixiao Song , Marzena Karpinska , John Wieting , Mohit Iyyer

Honeypots are decoy systems that lure attackers by presenting them with a seemingly vulnerable system. They provide an early detection mechanism as well as a method for learning how adversaries work and think. However, over the last years,…

密码学与安全 · 计算机科学 2021-09-23 Shreyas Srinivasa , Jens Myrup Pedersen , Emmanouil Vasilomanolakis

Keyloggers remain a serious threat in modern cybersecurity, silently capturing user keystrokes to steal credentials and sensitive information. Traditional defenses focus mainly on detection and removal, which can halt malicious activity but…

密码学与安全 · 计算机科学 2025-08-07 Md Sajidul Islam Sajid , Shihab Ahmed , Ryan Sosnoski
‹ 上一页 1 2 3 10 下一页 ›