Analyzing the usage of character groups and keyboard patterns in password creation
Purpose: Using passwords to keep account and data safe is very common in modern computing. The purpose of this paper is to look into methods for cracking passwords as a means of increasing security, a practice commonly used in penetration testing. Further, in the discipline of digital forensics, password cracking is often an essential part of a computer examination as data has to be decrypted to be analyzed. This paper seeks to look into how users that actively encrypt data construct their passwords to benefit the forensics community. Design/methodology/approach: The study began with an automated analysis of over one billion passwords in 22 different password databases that leaked to the internet. The study validated the result with an experiment were passwords created on a local website was analyzed during account creation. Further a survey was used to gather data that was used to identify differences in password behavior between user that actively encrypt their data and other users. Findings: The result of this study suggests that American lowercase letters and numbers are present in almost every password and that users seem to avoid using special characters if they can. Further, the study suggests that users that actively encrypt their data are more prone to use keyboard patterns as passwords than other users. Originality/value: This paper contributes to the existing body of knowledge around password behavior and suggests that password-guessing attacks should focus on American letters and numbers. Further, the paper suggests that forensics experts should consider testing patterns-based passwords when performing password-guessing attacks against encrypted data.
Year of publication: |
2020
|
---|---|
Authors: | Kävrestad, Joakim ; Zaxmy, Johan ; Nohlberg, Marcus |
Published in: |
Information & Computer Security. - Emerald, ISSN 2056-4961, ZDB-ID 2810936-3. - Vol. 28.2020, 3 (02.01.), p. 347-358
|
Publisher: |
Emerald |
Saved in:
Saved in favorites
Similar items by person
-
Exploring the meaning of usable security – a literature review
Lennartsson, Markus, (2021)
-
Understanding passwords – a taxonomy of password creation strategies
Kävrestad, Joakim, (2019)
-
Constructing secure and memorable passwords
Kävrestad, Joakim, (2020)
- More ...