信息网络安全 ›› 2019, Vol. 19 ›› Issue (8): 1-7.doi: 10.3969/j.issn.1671-1122.2019.08.001

• 等级保护 •    下一篇

基于主题PCFG的口令猜测模型研究

毕红军1, 谭儒1,2, 赵建军2,3(), 李昱甫2   

  1. 1.北京交通大学电子信息工程学院,北京 100044
    2.中国科学院信息工程研究所,北京 100093
    3.中国科学院大学网络空间安全学院,北京 100049
  • 收稿日期:2019-05-18 出版日期:2019-08-10 发布日期:2020-05-11
  • 作者简介:

    作者简介:毕红军(1965—),男,北京,副教授,硕士,主要研究方向为网络安全、信息网络、电子与通信工程;谭儒(1992—),男,湖南,硕士研究生,主要研究方向为网络安全;赵建军(1990—),男,甘肃,博士研究生,主要研究方向为Web安全、口令猜解;李昱甫(1997—),男,河南,本科,主要研究方向为Web安全、大数据分析。

  • 基金资助:
    北京市科技计划[D181100000618002]

Research on Password Guessing Model Based on Theme PCFG

Hongjun BI1, Ru TAN1,2, Jianjun ZHAO2,3(), Yufu LI2   

  1. 1. School of Electronic and Information Engineering, Beijing Jiaotong University, Beijing 100044, China
    2. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
    3. School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China
  • Received:2019-05-18 Online:2019-08-10 Published:2020-05-11

摘要:

口令是一种重要的身份认证方式,用户为了能够方便记住口令,常把一些与人相关的要素信息加入口令中。传统基于概率上下文无关文法(PCFG)算法进行的口令安全评估,并没有关注用户兴趣爱好、文化背景等与人相关的主题因素。文章基于传统PCFG算法,重点针对口令字母字段进行分析研究,通过对所收集的数据库字母字段的对比,提取用户口令与主题的关系,进而提出基于主题PCFG的口令猜测模型——T-PCFG模型。文章围绕收集的7个数据库中的3300万口令数据集进行实验,结果显示,主题为兴趣爱好时口令的猜测成功率比普通口令的猜测成功率高2.37~8.2个百分点。

关键词: 概率上下文无关文法, 口令, 主题, 口令猜测, 口令安全

Abstract:

Password is an important method of identity authentication. In order to be able to remember passwords conveniently, users often add some related information about people to passwords. Traditional password security assessment based on probabilistic context free grammar(PCFG) does not pay attention to user-related subject factors such as user hobbies and cultural backgrounds. Based on the traditional PCFG algorithm, this paper focuses on the analysis of the password letter field. By comparing the collected database letter fields, the relationship between the user password and the subject is extracted, and then the password guessing model based on the theme PCFG is proposed T-PCFG model. The article carried out experiments on the 33 million passwords collected from the seven databases. The results show that when the subject is a hobby, the success rate of password guessing is 2.37~8.2 percentage points higher than the normal one.

Key words: PCFG, password, theme, password guess, password security

中图分类号: