Your Email Address Holds the Key: Understanding the Connection Between Email and Password Security with Deep Learning

06/14/2023
by   Etienne Salimbeni, et al.
0

In this work, we investigate the effectiveness of deep-learning-based password guessing models for targeted attacks on human-chosen passwords. In recent years, service providers have increased the level of security of users'passwords. This is done by requiring more complex password generation patterns and by using computationally expensive hash functions. For the attackers this means a reduced number of available guessing attempts, which introduces the necessity to target their guess by exploiting a victim's publicly available information. In this work, we introduce a context-aware password guessing model that better capture attackers'behavior. We demonstrate that knowing a victim's email address is already critical in compromising the associated password and provide an in-depth analysis of the relationship between them. We also show the potential of such models to identify clusters of users based on their password generation behaviour, which can spot fake profiles and populations more vulnerable to context-aware guesses. The code is publicly available at https://github.com/spring-epfl/DCM_sp

READ FULL TEXT

page 1

page 2

page 4

page 6

page 8

page 9

page 11

research
10/21/2020

Deep learning based registration using spatial gradients and noisy segmentation labels

Image registration is one of the most challenging problems in medical im...
research
10/16/2020

Input-Aware Dynamic Backdoor Attack

In recent years, neural backdoor attack has been considered to be a pote...
research
07/21/2022

Knowledge-enhanced Black-box Attacks for Recommendations

Recent studies have shown that deep neural networks-based recommender sy...
research
10/06/2020

InstaHide: Instance-hiding Schemes for Private Distributed Learning

How can multiple distributed entities collaboratively train a shared dee...
research
06/03/2022

Evaluating Transfer-based Targeted Adversarial Perturbations against Real-World Computer Vision Systems based on Human Judgments

Computer vision systems are remarkably vulnerable to adversarial perturb...
research
06/01/2023

UNGOML: Automated Classification of unsafe Usages in Go

The Go programming language offers strong protection from memory corrupt...
research
06/01/2023

ModelObfuscator: Obfuscating Model Information to Protect Deployed ML-based Systems

More and more edge devices and mobile apps are leveraging deep learning ...

Please sign up or login with your details

Forgot password? Click here to reset