用社交数据重建+大模型分析密码强度,更准也更危险
Password Strength Analysis Through Social Network Data Exposure: A Combined Approach Relying on Data Reconstruction and Generative Models
- 结合社交数据与大模型重建用户密码特征
- 100人实验显示大模型能生成强且个性化的密码
- 适合安全研究者和密码策略设计者参考
尽管密码仍是防止未授权访问的主要手段,用户常选择易记密码,显著增加安全风险,且传统密码强度评估方法往往不足。本文提出SODA ADVANCE,一款数据重建工具,用于增强密码强度评估。该工具整合专用模块,利用社交媒体等公开数据源评估密码强度。同时,我们研究了大型语言模型(LLMs)在密码评估与生成中的能力与风险。对100名真实用户的实验表明,LLMs可基于用户画像生成强且个性化的密码;且当可获取用户画像数据时,其密码评估效果更佳。
原文摘要 · Abstract (English)
Although passwords remain the primary defense against unauthorized access, users often tend to use passwords that are easy to remember. This behavior significantly increases security risks, also due to the fact that traditional password strength evaluation methods are often inadequate. In this discussion paper, we present SODA ADVANCE, a data reconstruction tool also designed to enhance evaluation processes related to the password strength. In particular, SODA ADVANCE integrates a specialized module aimed at evaluating password strength by leveraging publicly available data from multiple sources, including social media platforms. Moreover, we investigate the capabilities and risks associated with emerging Large Language Models (LLMs) in evaluating and generating passwords, respectively. Experimental assessments conducted with 100 real users demonstrate that LLMs can generate strong and personalized passwords possibly defined according to user profiles. Additionally, LLMs were shown to be effective in evaluating passwords, especially when they can take into account user profile data.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。