Sharing Susceptible Passwords as Cyber Threat Intelligence Feed
Iman Vakilinia, Sui Cheung, Shamik Sengupta
Abstract
Iman Vakilinia, Sui Cheung, Shamik Sengupta
Abstract
Password-strength checkers provide feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber threat intelligence feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.
OpenAlex reports 17 citations for this work. Citation counts describe recorded attention and do not establish research quality.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
Password-strength checkers provide feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber threat intelligence feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.
Key concepts: Password, Computer science, Cognitive password, Password cracking, Password strength, Dictionary attack, Honeypot, Computer security