Passwords have been and will likely going to remain as the main authentication mechanism for system security. Many modern organisations are often overwhelmed by the issue of maintaining secured passwords in and across large heterogeneous environments, often containing Microsoft Active Directory, Linux, UNIX, IBM System Z, SAP, etc. To manage and strengthen the password security, password auditing systems have been introduced to audit the strength of organization’s password and its importance is increasing over time. Despite its criticality, there is a lack of methodologies proposed for assessing the security of password auditing systems in literature. In this paper, we proposed replicable heuristics for testing password auditing systems. As a representative industry use case, we evaluated EPAS (Enterprise Password Assessment Solution) system, a next-generation password auditing system that is internationally used by governments and organizations. In the first heuristic, packet sniffing, remote code execution and brute-force attacks for different interfaces were conducted to prove the EPAS system’s security validation. In the second heuristic, an optimization test leveraging machine learning model training and Large Language Model-powered password candidate generation validated EPAS’ robustness and modern password-recovery technique. The results show secured stability of the system and, by including AI modes, an improvement in password recovery efficiency.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Auditing the Auditor: Heuristics for Testing Password Auditing System Security

  • Taejun Choi,
  • Daniel van Niekerk,
  • Octav Opaschi,
  • Costin Enache,
  • Ryan K. L. Ko

摘要

Passwords have been and will likely going to remain as the main authentication mechanism for system security. Many modern organisations are often overwhelmed by the issue of maintaining secured passwords in and across large heterogeneous environments, often containing Microsoft Active Directory, Linux, UNIX, IBM System Z, SAP, etc. To manage and strengthen the password security, password auditing systems have been introduced to audit the strength of organization’s password and its importance is increasing over time. Despite its criticality, there is a lack of methodologies proposed for assessing the security of password auditing systems in literature. In this paper, we proposed replicable heuristics for testing password auditing systems. As a representative industry use case, we evaluated EPAS (Enterprise Password Assessment Solution) system, a next-generation password auditing system that is internationally used by governments and organizations. In the first heuristic, packet sniffing, remote code execution and brute-force attacks for different interfaces were conducted to prove the EPAS system’s security validation. In the second heuristic, an optimization test leveraging machine learning model training and Large Language Model-powered password candidate generation validated EPAS’ robustness and modern password-recovery technique. The results show secured stability of the system and, by including AI modes, an improvement in password recovery efficiency.