{"id":"https://openalex.org/W2054626033","doi":"https://doi.org/10.1109/sp.2012.38","title":"Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms","display_name":"Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms","publication_year":2012,"publication_date":"2012-05-01","ids":{"openalex":"https://openalex.org/W2054626033","doi":"https://doi.org/10.1109/sp.2012.38","mag":"2054626033"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp.2012.38","pdf_url":null,"source":{"id":"https://openalex.org/S4306418833","display_name":"IEEE Symposium on Security and Privacy","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"http://www.cylab.cmu.edu/files/pdfs/tech_reports/CMUCyLab11008.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5018021084","display_name":"Patrick Gage Kelley","orcid":"https://orcid.org/0000-0003-4405-0010"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Patrick Gage Kelley","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5048460404","display_name":"Saranga Komanduri","orcid":null},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Saranga Komanduri","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5105206771","display_name":"Michelle L. Mazurek","orcid":"https://orcid.org/0000-0003-4151-6428"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Michelle L. Mazurek","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077826909","display_name":"Richard Shay","orcid":"https://orcid.org/0000-0002-9437-9802"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Richard Shay","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5087984415","display_name":"Timothy Vidas","orcid":null},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Timothy Vidas","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5002939847","display_name":"Lujo Bauer","orcid":"https://orcid.org/0000-0002-8209-6792"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lujo Bauer","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078075278","display_name":"Nicolas Christin","orcid":"https://orcid.org/0000-0002-2506-8031"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Nicolas Christin","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072760035","display_name":"Lorrie Faith Cranor","orcid":"https://orcid.org/0000-0003-2125-0124"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Lorrie Faith Cranor","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5040849996","display_name":"Julio L\u00f3pez","orcid":"https://orcid.org/0000-0001-5139-0158"},"institutions":[{"id":"https://openalex.org/I74973139","display_name":"Carnegie Mellon University","ror":"https://ror.org/05x2bcf33","country_code":"US","type":"education","lineage":["https://openalex.org/I74973139"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Julio Lopez","raw_affiliation_strings":["Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Carnegie-Mellon University, Pittsburgh, Pa., USA#TAB#","institution_ids":["https://openalex.org/I74973139"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":23.646,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":374,"citation_normalized_percentile":{"value":0.99982,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"523","last_page":"537"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9979,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11519","display_name":"Digital Mental Health Interventions","score":0.9822,"subfield":{"id":"https://openalex.org/subfields/3202","display_name":"Applied Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/password-cracking","display_name":"Password cracking","score":0.773357},{"id":"https://openalex.org/keywords/cognitive-password","display_name":"Cognitive password","score":0.6815947},{"id":"https://openalex.org/keywords/zero-knowledge-password-proof","display_name":"Zero-knowledge password proof","score":0.4917927}],"concepts":[{"id":"https://openalex.org/C109297577","wikidata":"https://www.wikidata.org/wiki/Q161157","display_name":"Password","level":2,"score":0.95791554},{"id":"https://openalex.org/C70530487","wikidata":"https://www.wikidata.org/wiki/Q1990841","display_name":"Password strength","level":4,"score":0.86254907},{"id":"https://openalex.org/C3847113","wikidata":"https://www.wikidata.org/wiki/Q2746524","display_name":"Password cracking","level":5,"score":0.773357},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.761153},{"id":"https://openalex.org/C23875713","wikidata":"https://www.wikidata.org/wiki/Q5141232","display_name":"Cognitive password","level":5,"score":0.6815947},{"id":"https://openalex.org/C98705547","wikidata":"https://www.wikidata.org/wiki/Q3394687","display_name":"Password policy","level":4,"score":0.65337443},{"id":"https://openalex.org/C89479133","wikidata":"https://www.wikidata.org/wiki/Q1137840","display_name":"One-time password","level":3,"score":0.5946159},{"id":"https://openalex.org/C4957475","wikidata":"https://www.wikidata.org/wiki/Q242186","display_name":"S/KEY","level":3,"score":0.5936845},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.57301515},{"id":"https://openalex.org/C188615804","wikidata":"https://www.wikidata.org/wiki/Q8069448","display_name":"Zero-knowledge password proof","level":5,"score":0.4917927},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.41570452}],"mesh":[],"locations_count":2,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/sp.2012.38","pdf_url":null,"source":{"id":"https://openalex.org/S4306418833","display_name":"IEEE Symposium on Security and Privacy","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.298.4842","pdf_url":"http://www.cylab.cmu.edu/files/pdfs/tech_reports/CMUCyLab11008.pdf","source":{"id":"https://openalex.org/S4306400349","display_name":"CiteSeer X (The Pennsylvania State University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I130769515","host_organization_name":"Pennsylvania State University","host_organization_lineage":["https://openalex.org/I130769515"],"host_organization_lineage_names":["Pennsylvania State University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.298.4842","pdf_url":"http://www.cylab.cmu.edu/files/pdfs/tech_reports/CMUCyLab11008.pdf","source":{"id":"https://openalex.org/S4306400349","display_name":"CiteSeer X (The Pennsylvania State University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I130769515","host_organization_name":"Pennsylvania State University","host_organization_lineage":["https://openalex.org/I130769515"],"host_organization_lineage_names":["Pennsylvania State University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[{"display_name":"Peace, justice, and strong institutions","score":0.43,"id":"https://metadata.un.org/sdg/16"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":47,"referenced_works":["https://openalex.org/W1487941708","https://openalex.org/W1503108337","https://openalex.org/W1548573590","https://openalex.org/W1551931061","https://openalex.org/W1566273181","https://openalex.org/W1572182570","https://openalex.org/W1577841485","https://openalex.org/W1582097881","https://openalex.org/W1598064945","https://openalex.org/W1600614774","https://openalex.org/W167157979","https://openalex.org/W1987516957","https://openalex.org/W1995875735","https://openalex.org/W2009226705","https://openalex.org/W2038368865","https://openalex.org/W2047917391","https://openalex.org/W2048584594","https://openalex.org/W2053030258","https://openalex.org/W2064327548","https://openalex.org/W2079145130","https://openalex.org/W2086553822","https://openalex.org/W2091833612","https://openalex.org/W2097267243","https://openalex.org/W2100142573","https://openalex.org/W2104749423","https://openalex.org/W2104773223","https://openalex.org/W2111374852","https://openalex.org/W2113266120","https://openalex.org/W2114269021","https://openalex.org/W2119545418","https://openalex.org/W2121386924","https://openalex.org/W2123097583","https://openalex.org/W2131589410","https://openalex.org/W2133968993","https://openalex.org/W2135359429","https://openalex.org/W2137244916","https://openalex.org/W2141708418","https://openalex.org/W2145881505","https://openalex.org/W2150341374","https://openalex.org/W2151401338","https://openalex.org/W2171920515","https://openalex.org/W2173213060","https://openalex.org/W2896709927","https://openalex.org/W4214501820","https://openalex.org/W42204834","https://openalex.org/W4298423176","https://openalex.org/W47516667"],"related_works":["https://openalex.org/W4302810031","https://openalex.org/W3131491961","https://openalex.org/W2969720675","https://openalex.org/W2953105088","https://openalex.org/W2596766976","https://openalex.org/W2021087413","https://openalex.org/W2017283799","https://openalex.org/W1995890708","https://openalex.org/W1982158666","https://openalex.org/W1970072309"],"abstract_inverted_index":{"Text-based":[0],"passwords":[1,56,91,112,122],"remain":[2],"the":[3,88,99,109,127,132],"dominant":[4],"authentication":[5],"method":[6,71],"in":[7,13],"computer":[8],"systems,":[9],"despite":[10],"significant":[11],"advancement":[12],"attackers'":[14],"capabilities":[15],"to":[16,22,39,46,96,125],"perform":[17],"password":[18,25,41,157],"cracking.":[19],"In":[20,50],"response":[21],"this":[23,51,83],"threat,":[24],"composition":[26,60,118],"policies":[27,61,152],"have":[28],"grown":[29],"increasingly":[30],"complex.":[31],"However,":[32],"there":[33],"is":[34],"insufficient":[35],"research":[36],"defining":[37],"metrics":[38,154],"characterize":[40],"strength":[42],"and":[43,120,130,142,153],"using":[44],"them":[45],"evaluate":[47],"password-composition":[48,151],"policies.":[49],"paper,":[52],"we":[53,85],"analyze":[54],"12,000":[55],"collected":[57],"under":[58,93,104,115],"seven":[59],"via":[62],"an":[63,68],"online":[64],"study.":[65],"We":[66],"develop":[67],"efficient":[69],"distributed":[70],"for":[72,155],"calculating":[73],"how":[74],"effectively":[75],"several":[76],"heuristic":[77],"password-guessing":[78],"algorithms":[79,103],"guess":[80,135],"passwords.":[81],"Leveraging":[82],"method,":[84],"investigate":[86],"(a)":[87],"resistance":[89],"of":[90,101,149],"created":[92,114],"different":[94,105],"conditions":[95],"guessing,":[97],"(b)":[98],"performance":[100],"guessing":[102],"training":[106],"sets,":[107],"(c)":[108],"relationship":[110,133],"between":[111,134],"explicitly":[113],"a":[116],"given":[117],"policy":[119],"other":[121],"that":[123],"happen":[124],"meet":[126],"same":[128],"requirements,":[129],"(d)":[131],"ability,":[136],"as":[137],"measured":[138],"with":[139],"password-cracking":[140],"algorithms,":[141],"entropy":[143],"estimates.":[144],"Our":[145],"findings":[146],"advance":[147],"understanding":[148],"both":[150],"quantifying":[156],"security.":[158]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2054626033","counts_by_year":[{"year":2024,"cited_by_count":10},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":16},{"year":2021,"cited_by_count":31},{"year":2020,"cited_by_count":40},{"year":2019,"cited_by_count":41},{"year":2018,"cited_by_count":33},{"year":2017,"cited_by_count":40},{"year":2016,"cited_by_count":31},{"year":2015,"cited_by_count":52},{"year":2014,"cited_by_count":39},{"year":2013,"cited_by_count":24},{"year":2012,"cited_by_count":9}],"updated_date":"2024-12-30T23:45:31.840961","created_date":"2016-06-24"}