Skip to main content
QUICK REVIEW

[論文レビュー] General Framework for Evaluating Password Complexity and Strength

Cem Şahin, Robert Lychev|arXiv (Cornell University)|Dec 17, 2015
User Authentication and Security Systems参考文献 25被引用数 4
ひとこと要約

本論文は、計算リソース、事前知識、およびムーアの法則のような進化する能力を含む攻撃者行動をモデル化することで、パスワードの複雑さと強度を区別し、計算する形式的フレームワークを提案する。FAT-strengthは、ストレージ関数、攻撃者パワー、およびユーザー定義の時間制限を用いて、破壊に要する時間を推定する仮説検定アプローチであり、従来のエントロピーまたはヒューリスティクスよりもより正確で現実的な測定を提供する。

ABSTRACT

Although it is common for users to select bad passwords that can be easily cracked by attackers, password-based authentication remains the most widely-used method. To encourage users to select good passwords, enterprises often enforce policies. Such policies have been proven to be ineffectual in practice. Accurate assessment of a password's resistance to cracking attacks is still an unsolved problem, and our work addresses this challenge. Although the best way to determine how difficult it may be to crack a user-selected password is to check its resistance to cracking attacks employed by attackers in the wild, implementing such a strategy at an enterprise would be infeasible in practice. We first formalize the concepts of password complexity and strength with concrete definitions emphasizing their differences. Our framework captures human biases and many known techniques attackers use to recover stolen credentials in real life, such as brute-force attacks. Building on our definitions, we develop a general framework for calculating password complexity and strength that could be used in practice. Our approach is based on the key insight that an attacker's success at cracking a password must be defined by its available computational resources, time, function used to store that password, as well as the topology that bounds that attacker's search space based on that attacker's available inputs, transformations it can use to tweak and explore its inputs, and the path of exploration which can be based on the attacker's perceived probability of success. We also provide a general framework for assessing the accuracy of password complexity and strength estimators that can be used to compare other tools available in the wild.

研究の動機と目的

  • 文献における長年の混乱を解消するため、パスワードの複雑さと強度を形式的に区別し定義すること。
  • 実世界のクラッキング攻撃に対する抵抗性を正確に推定するという、長年の課題に対処すること。
  • 攻撃者能力、事前知識、進化する技術(例:ムーアの法則)を組み込んだ実用的フレームワークを開発すること。
  • 標準化された評価メカニズムを通じて、既存のパスワード強度推定ツールの客観的比較を可能にすること。
  • パスワード保護システムの強度を評価することで、安全なストレージおよび認証を支援すること。

提案手法

  • 攻撃者制約(計算パワー、時間、事前知識、パスワードストレージ関数)を明示的にモデル化したパスワード複雑さと強度の形式的定義。
  • 事前知識と変換ルールによって制限される、攻撃者探索空間を表すトポロジーに基づくモデルの導入。
  • ルールの順列を用いたチェーンルールベースの複雑さ計算により、パスワードエントロピーの下限と上限を推定。
  • 仮説検定を用いたFAT-strengthの開発:Eq. 7に基づくH₁(FAT-strong)とH₀(FAT-strongでない)の比較、時間別に要する時間T、攻撃者パワーs(t)、およびユーザー定義のTを考慮。
  • ムーアの法則をs(t)に統合し、時間経過に伴う計算パワーの増加をモデル化し、動的強度推定を可能にする。
  • ワンウェイハッシュなど、さまざまなパスワード保護手法および認証システムをサポートするフレームワークの一般化。

実験結果

リサーチクエスチョン

  • RQ1攻撃者行動の現実を反映する形で、パスワードの複雑さと強度を形式的に区別し定義する方法は何か?
  • RQ2人間のバイアスおよび既知の攻撃手法(例:変形ワードリスト、マルコフモデル)は、パスワードクラッキング耐性にどのような影響を与えるか?
  • RQ3ムーアの法則が予測するような進化する計算能力下で、破壊に要する時間を正確に推定する方法は何か?
  • RQ4既存のパスワード強度推定ツールを評価・比較できる統一されたフレームワークを構築できるか?
  • RQ5このフレームワークは、パスワード保護情報のストレージを行うシステムのセキュリティを評価するためにどのように応用できるか?

主な発見

  • 本フレームワークは、文字セット、長さ、対称性に基づく複雑さと、攻撃者能力およびストレージ方法を含む強度を形式的に分離し、長年の概念的混乱を解消した。
  • ルールと変換のトポロジーを用いて攻撃者探索空間をモデル化することで、人間のバイアスを考慮した複雑さの下限推定が可能になった。
  • FAT-strength指標は、Eq. 7に基づく仮説検定を用い、攻撃者計算パワーs(t)、ユーザー定義の破壊時間T、ストレージ関数Fを統合して、パスワードが暗号的に強いかどうかを判定する。
  • モデルは、2045年までに攻撃者の計算パワーが2015年比で32,768倍に達する可能性があると予測し、より強いパスワードが使われない限り、破壊時間は著しく短縮される。
  • 攻撃者中心の評価メカニズムを提供するため、既存のパスワード強度メーターの比較が可能になった。
  • ユーザー固有のデータ(例:ソーシャルメディア)をルール集合Ξに統合できるため、実用的導入が可能で、強度推定の現実性が向上した。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。