Netinfo Security ›› 2019, Vol. 19 ›› Issue (8): 1-7.doi: 10.3969/j.issn.1671-1122.2019.08.001

    Next Articles

Research on Password Guessing Model Based on Theme PCFG

Hongjun BI1, Ru TAN1,2, Jianjun ZHAO2,3(), Yufu LI2   

  1. 1. School of Electronic and Information Engineering, Beijing Jiaotong University, Beijing 100044, China
    2. Institute of Information Engineering, Chinese Academy of Sciences, Beijing 100093, China
    3. School of Cyber Security, University of Chinese Academy of Sciences, Beijing 100049, China
  • Received:2019-05-18 Online:2019-08-10 Published:2020-05-11

Abstract:

Password is an important method of identity authentication. In order to be able to remember passwords conveniently, users often add some related information about people to passwords. Traditional password security assessment based on probabilistic context free grammar(PCFG) does not pay attention to user-related subject factors such as user hobbies and cultural backgrounds. Based on the traditional PCFG algorithm, this paper focuses on the analysis of the password letter field. By comparing the collected database letter fields, the relationship between the user password and the subject is extracted, and then the password guessing model based on the theme PCFG is proposed T-PCFG model. The article carried out experiments on the 33 million passwords collected from the seven databases. The results show that when the subject is a hobby, the success rate of password guessing is 2.37~8.2 percentage points higher than the normal one.

Key words: PCFG, password, theme, password guess, password security

CLC Number: