Despite the ineffectiveness of enforcing specific password policies, the influence of long-standing recommendations persists. Many companies advise avoiding dictionary words and promoting the use of misspellings or nonstandard spellings. This study is the first to examine the impact of misspellings in offline password cracking, introducing two novel techniques for generating similar-sounding misspellings using the linguistic concept of homophones. The first technique, ProbP2G, uses phoneme-grapheme correspondences, while the second, LSTM-P2G, employs a deep learning model for phoneme-to-grapheme conversion. We expand attack dictionaries with these homophones and evaluate their impact on password cracking across multiple datasets. Our results show that incorporating these misspellings significantly improves cracking success, highlighting the vulnerabilities in current password policies and offering a new approach to creating more effective attack dictionaries.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Generating and Attacking Passwords with Misspellings by Leveraging Homophones

  • Shiva Houshmand,
  • Smita Ghosh,
  • Jared Maeyama

摘要

Despite the ineffectiveness of enforcing specific password policies, the influence of long-standing recommendations persists. Many companies advise avoiding dictionary words and promoting the use of misspellings or nonstandard spellings. This study is the first to examine the impact of misspellings in offline password cracking, introducing two novel techniques for generating similar-sounding misspellings using the linguistic concept of homophones. The first technique, ProbP2G, uses phoneme-grapheme correspondences, while the second, LSTM-P2G, employs a deep learning model for phoneme-to-grapheme conversion. We expand attack dictionaries with these homophones and evaluate their impact on password cracking across multiple datasets. Our results show that incorporating these misspellings significantly improves cracking success, highlighting the vulnerabilities in current password policies and offering a new approach to creating more effective attack dictionaries.