2018Unpublished venueRequires access

Sharing Susceptible Passwords as Cyber Threat Intelligence Feed

Iman Vakilinia, Sui Cheung, Shamik Sengupta

Open publisher page 17 citations

Abstract

Password-strength checkers provide feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber threat intelligence feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

About this research paper

What this paper is about

Password-strength checkers provide feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber threat intelligence feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

Why it matters

OpenAlex reports 17 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Password-strength checkers provide feedback to users about their password choice. Several parameters are investigated by password-strength checkers such as length, character set, user information, and entropy to score the chosen password. Moreover, such checkers use dictionaries to detect susceptible passwords such as keyboard sequences (e.g. qwert), simple and usual words (e.g. password). As the password patterns are language specific, having an English dictionary of patterns is not helpful to detect other language patterns. Besides that, the users' passwords choice might be inspired by the new patterns emerging in their culture. For instance, new movies, books, and games. Hence, the dictionary needs to be updated to cover the new patterns. However, generating such dictionaries which cover new and diverse patterns is not simple and needs excessive efforts to extract new patterns from different cultures. To update the list of susceptible passwords and extract new password patterns dynamically, we propose a method for sharing attacked passwords which are collected from the honeypot through brute-force attack attempts. To achieve this goal, first, we analyze the passwords collected in brute-force attack attempted in our honeypot. Then, we model the password sharing as cyber threat intelligence feed in the Structured Threat Information Expression (STIX) format. We also provide a tool which allows users to query if a string or its leet transformation is existing in the susceptible password dataset.

Key concepts: Password, Computer science, Cognitive password, Password cracking, Password strength, Dictionary attack, Honeypot, Computer security

Related papers

Back to paper searchBrowse research topicsOriginal source
Sharing Susceptible Passwords as Cyber Threat Intelligence Feed — Research Paper | ScholarLens