about
Improving Password Guessing via Representation Learning (arxiv.org)
3 points by sel1 on Oct 13, 2019 | hide | past | pdf | discuss on HN

In plain words: A deep generative model learns an abstract code for passwords, letting it create guesses in ways older probability-based and rule-based guessers cannot. It can steer guesses toward any chosen bias and shift to match the passwords actually being attacked.

Abstract

Learning useful representations from unstructured data is one of the core challenges, as well as a driving force, of modern data-driven approaches. Deep learning has demonstrated the broad advantages of learning and harnessing such representations. In this paper, we introduce a deep generative model representation learning approach for password guessing. We show that an abstract password representation naturally offers compelling and versatile properties that can be used to open new directions in the extensively studied, and yet presently active, password guessing field. These properties can establish novel password generation techniques that are neither feasible nor practical with the existing probabilistic and non-probabilistic approaches. Based on these properties, we introduce:(1) A general framework for conditional password guessing that can generate passwords with arbitrary biases; and (2) an Expectation Maximization-inspired framework that can dynamically adapt the estimated password distribution to match the distribution of the attacked password set.

Dario Pasquini, Ankit Gangwal, Giuseppe Ateniese, Massimo Bernaschi, Mauro Conti
arXiv:1910.04232 · cs.CR · submitted Oct 9, 2019 · updated Jul 26, 2020
abstract · pdf · html · This paper appears in the proceedings of the 42nd IEEE Symposium on Security and Privacy (Oakland) S&P 2021

add comment on HN