Cracking-Resistant Password Vaults Using Natural

Published  . 0 views
↓ Download
Cracking-Resistant Password Vaults Using Natural
1 / 1
Cracking-Resistant Password Vaults Using Natural - slide 1 of 62 Cracking-Resistant Password Vaults Using Natural - slide 2 of 62 Cracking-Resistant Password Vaults Using Natural - slide 3 of 62 Cracking-Resistant Password Vaults Using Natural - slide 4 of 62 Cracking-Resistant Password Vaults Using Natural - slide 5 of 62 Cracking-Resistant Password Vaults Using Natural - slide 6 of 62 Cracking-Resistant Password Vaults Using Natural - slide 7 of 62 Cracking-Resistant Password Vaults Using Natural - slide 8 of 62 Cracking-Resistant Password Vaults Using Natural - slide 9 of 62 Cracking-Resistant Password Vaults Using Natural - slide 10 of 62 Cracking-Resistant Password Vaults Using Natural - slide 11 of 62 Cracking-Resistant Password Vaults Using Natural - slide 12 of 62 Cracking-Resistant Password Vaults Using Natural - slide 13 of 62 Cracking-Resistant Password Vaults Using Natural - slide 14 of 62 Cracking-Resistant Password Vaults Using Natural - slide 15 of 62 Cracking-Resistant Password Vaults Using Natural - slide 16 of 62 Cracking-Resistant Password Vaults Using Natural - slide 17 of 62 Cracking-Resistant Password Vaults Using Natural - slide 18 of 62 Cracking-Resistant Password Vaults Using Natural - slide 19 of 62 Cracking-Resistant Password Vaults Using Natural - slide 20 of 62 Cracking-Resistant Password Vaults Using Natural - slide 21 of 62 Cracking-Resistant Password Vaults Using Natural - slide 22 of 62 Cracking-Resistant Password Vaults Using Natural - slide 23 of 62 Cracking-Resistant Password Vaults Using Natural - slide 24 of 62 Cracking-Resistant Password Vaults Using Natural - slide 25 of 62 Cracking-Resistant Password Vaults Using Natural - slide 26 of 62 Cracking-Resistant Password Vaults Using Natural - slide 27 of 62 Cracking-Resistant Password Vaults Using Natural - slide 28 of 62 Cracking-Resistant Password Vaults Using Natural - slide 29 of 62 Cracking-Resistant Password Vaults Using Natural - slide 30 of 62 Cracking-Resistant Password Vaults Using Natural - slide 31 of 62 Cracking-Resistant Password Vaults Using Natural - slide 32 of 62 Cracking-Resistant Password Vaults Using Natural - slide 33 of 62 Cracking-Resistant Password Vaults Using Natural - slide 34 of 62 Cracking-Resistant Password Vaults Using Natural - slide 35 of 62 Cracking-Resistant Password Vaults Using Natural - slide 36 of 62 Cracking-Resistant Password Vaults Using Natural - slide 37 of 62 Cracking-Resistant Password Vaults Using Natural - slide 38 of 62 Cracking-Resistant Password Vaults Using Natural - slide 39 of 62 Cracking-Resistant Password Vaults Using Natural - slide 40 of 62 Cracking-Resistant Password Vaults Using Natural - slide 41 of 62 Cracking-Resistant Password Vaults Using Natural - slide 42 of 62 Cracking-Resistant Password Vaults Using Natural - slide 43 of 62 Cracking-Resistant Password Vaults Using Natural - slide 44 of 62 Cracking-Resistant Password Vaults Using Natural - slide 45 of 62 Cracking-Resistant Password Vaults Using Natural - slide 46 of 62 Cracking-Resistant Password Vaults Using Natural - slide 47 of 62 Cracking-Resistant Password Vaults Using Natural - slide 48 of 62 Cracking-Resistant Password Vaults Using Natural - slide 49 of 62 Cracking-Resistant Password Vaults Using Natural - slide 50 of 62 Cracking-Resistant Password Vaults Using Natural - slide 51 of 62 Cracking-Resistant Password Vaults Using Natural - slide 52 of 62 Cracking-Resistant Password Vaults Using Natural - slide 53 of 62 Cracking-Resistant Password Vaults Using Natural - slide 54 of 62 Cracking-Resistant Password Vaults Using Natural - slide 55 of 62 Cracking-Resistant Password Vaults Using Natural - slide 56 of 62 Cracking-Resistant Password Vaults Using Natural - slide 57 of 62 Cracking-Resistant Password Vaults Using Natural - slide 58 of 62 Cracking-Resistant Password Vaults Using Natural - slide 59 of 62 Cracking-Resistant Password Vaults Using Natural - slide 60 of 62 Cracking-Resistant Password Vaults Using Natural - slide 61 of 62 Cracking-Resistant Password Vaults Using Natural - slide 62 of 62
Description: Cracking-Resistant Password Vaults Using Natural Language Encoders Password Vaults (a.k.a Password Manager) mypass4 Plaintext Vault Encrypted Vault family00 family01 family.1 qwerty poiuyt.12 PKCS5 encryption 0xe1f3f4a 0x73bc52e

Related Topics

Download Presentation

"Cracking-Resistant Password Vaults Using Natural" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Cracking-Resistant Password Vaults Using Natural Language Encoders<br>
slide2. Password Vaults (a.k.a Password Manager) mypass4 Plaintext Vault Encrypted Vault family00
family01
family.1
qwerty
poiuyt.12 PKCS#5
encryption 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Cloud Storage Master password<br>
slide3. Password Vaults Increasing in Popularity And many more….<br>
slide4. Server Compromise
L. Whitney, “LastPass CEO reveals details on security breach,” CNet, May 2011.
Exfiltration from Client Machine
Z. Li et al., “The emperor’s new password manager: Security analysis of web-based password managers,” USENIX Security, 2014. Stealing Password Vaults mypass4 Plaintext Vault Encrypted Vault Cloud Storage family00
family01
family.1
qwerty
poiuyt.12 PKCS#5 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Stealing Vault<br>
slide5. Offline Brute Force Attack 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Decryption
(PKCS#5) 趬?%?U? Á
ऑޕ؆ॠؕीڐʁޕ؆ࠔॠؕ?ीڐʁ ɠڅ՗ݸՙдͩؓ३sU%aհ̰ԹЂء҅փٖ Vault Ciphertext Output of Decryption 123456
password
iloveyou



mypass4
abc123
nicole
Daniel
.
.
. Attacker’s guesses Random Junk<br>
slide6. Offline Brute Force Attack 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Decryption
(PKCS#5) ?%?U?ऑޕ؆ॠؕीڐʁ Á趭؆ॠؕ?aڐʁ 购փЩͣɠڅ३sU%հ̰ԹЂءٖ?%a Vault Ciphertext Output of Decryption 123456
password
iloveyou



mypass4
abc123
nicole
Daniel
.
.
. Random Junk Attacker’s guesses<br>
slide7. Offline Brute Force Attack 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Decryption
(PKCS#5) ऑޕ؆ॠؕीڐ770&c#a&a339019f*aؕ?ीڐʁڅ՗ݸՙдͩؓ३U%հ̰ԹЂء҅փ Vault Ciphertext Output of Decryption 123456
password
iloveyou



mypass4
abc123
nicole
Daniel
.
.
. Random Junk Attacker’s guesses<br>
slide8. Offline Brute Force Attack 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 123456
password
iloveyou



mypass4
abc123
nicole
Daniel
.
.
. Decryption
(PKCS#5) family00
family01
family.1
qwerty
poiuyt.12 Vault Ciphertext Output of Decryption [*] Hashing and salting slows down by small factor. Yes, this is it. Runtime of the attack =
# of decryption attempts
Offline Work* Attacker’s guesses<br>
slide9. So What ?!? Lose Your Vault Lose Your Passwords = 70% of passwords can be cracked <1bn guesses [3] [3] R. Veras, C. Collins, and J. Thorpe, “On the semantic patterns of passwords and their security impact,” in NDSS, 2014.<br>
slide10. Our Contribution Goal:
Prevent offline attack on password vaults
How ?
Decoy Techniques
Show existing decoy techniques have a subtle vulnerability
Kamouflage by Bojinov et al. can degrade security compared to standard password-based encryption
Build a new mechanism: Natural Language Encoder (NLE)
Honey Encryption
NoCrack: new password vault system with decoys<br>
slide11. Kamouflage abcdef12
abcdef02
abcdef#1
thomas
temple#00 travis99
travis12
travis@7
soccer smiles@33 family00
family01
family.1
qwerty poiuyt.12 scooby33
scooby45
scooby@3
vanbus weiwei!69 shishi1 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… violet9 mypass4 zxcvbn9 PKCS#5 PKCS#5 PKCS#5 PKCS#5 Vault Ciphertext N = 4
(3 decoy vaults)<br>
slide12. Kamouflage 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Kamouflage
Decryption Real Vault, when
mpw = real password mpw Decoy Vault, when
mpw  decoy passwords Junk
None of the above N = 4
(3 decoy vaults)<br>
slide13. Kamouflage
Vault Ciphertext 123456
password
Iloveyou


violet9


mypass4
abc123
nicole
Daniel
.
.
. Kamouflage
Decryption ɡɠڅ0&c#a&a339019f*a2;19dd229趬6%7a'82c0%ф݇ःФs? Random Junk Attacker guesses Brute-Forcing Kamouflage<br>
slide14. Kamouflage
Vault Ciphertext 123456
password
Iloveyou


violet9


mypass4
abc123
nicole
Daniel
.
.
. Kamouflage
Decryption travis99
travis12
travis@7
soccer smiles@33 Decoy Vault Brute-Forcing Kamouflage Attacker guesses<br>
slide15. Kamouflage
Vault Ciphertext 123456
password
Iloveyou


violet9


mypass4
abc123
nicole
Daniel
.
.
. Kamouflage
Decryption family00
family01
family.1
qwerty poiuyt.12 Real Vault Attacker guesses Brute-Forcing Kamouflage<br>
slide16. The Naïve Attack Runtime of the Attack =
Offline Work of PBE + N/2 Online Work
(N = # of explicitly stored vaults) abcdef12
abcdef02
abcdef#1
thomas
temple#00 travis99
travis12
travis@7
soccer smiles@33 family00
family01
family.1
qwerty poiuyt.12 scooby33
scooby45
scooby@3
vanbus weiwei!69 To check if vault is real or decoy: login attempt using password Kamouflage security claim:
naïve attack is the best possible ? shishi1 violet9 mypass4 zxcvbn9<br>
slide17. Real But... WE FOUND A PROBLEM IN THE DECOY GENERATION family00
family01
family.1
qwerty poiuyt.12 abcdef12
abcdef02
abcdef#1
thomas
temple#00 travis99
travis12
travis@7
soccer smiles@33 scooby33
scooby45
scooby!3
vanbus weiwei!69 mypass4 .... { Decoys violet9 zxcvbn9 shishi1<br>
slide18. Attacking Kamouflage Kamouflage
Vault …

veronica
viper01
violet9 whatsup!
Wlidcat2
year2012
secret7


mypass4 Kamouflage
Decryption ࠕѦܷ३ءф֗ʅɤ؉Ѱॸݢաܢٓं֑٠є͈̇Ճऒиࡲेѓঀ१Җ֒РԄΙҀݹऩݠޔձԴ?%U Attacker guesses Random Junk Random Junk<br>
slide19. Attacking Kamouflage Kamouflage
Vault Kamouflage
Decryption Plausible Vault …

veronica
viper01
violet9 whatsup!
Wlidcat2
year2012
secret7


mypass4 travis99
travis12
travis#7
soccer smiles#33 Master Password has 6 characters, followed by 1 digit. Check violet9 with online query Big speed up If not, move to next master password w/ structure Attacker guesses<br>
slide20. Attack Results Kamouflage claimed (for N=103):
100% offline work of standard Password Based Encryption
+
N/2 = 500 expected online queries

Simulations with Yahoo password leak:
50% offline work of standard Password Based Encryption
+
11 expected online queries<br>
slide21. The situation so far… Standard encryption vulnerable to brute force attacks

Kamouflage can be less secure than standard encryption<br>
slide22. Honey Encryption by Juels and Ristenpart, EUROCRYPT 2014 Decryption with any key outputs plausible plaintext m Encode Encrypt C key s Bit string<br>
slide23. Honey Encryption by Juels and Ristenpart, EUROCRYPT 2014 m Decode Decrypt key S C m’ Decode Decrypt key’ S’ Decryption with any key outputs plausible plaintext<br>
slide24. Honey Encryption by Juels and Ristenpart, EUROCRYPT 2014 C m’ Decode Decrypt key S m Encode Encrypt C key s Key technical challenge:
building secure encoders Decryption with any key outputs plausible plaintext<br>
slide25. Natural Language Encoder (NLE) Bit-string Security (informally):
No attacker can distinguish between decode of random S’ and a true, freshly chosen plaintext<br>
slide26. Modern Password Crackers Training Password Leaks Better Password Model  Better Crackers Model of password distribution 123456
password
iloveyou

… Cracker Use model to sample
passwords in the order
of their likelihood [Weir et al. 2010] [Veras et al. 2014] …<br>
slide27. pw Decode S Password-model Based NLEs We show how to use common password models to build NLEs
N-gram Markov models
Probabilistic Context-Free Grammars (PCFGs)
Handling related passwords in vaults W6 violet S D1 9 High level idea:
Encode random path through
PCFG as uniform-looking bit string

Decode uses input to choose a random
parse tree from PCFG

See paper for details Better Password Model  Better Decoys<br>
slide28. NoCrack (a new kind of password vault) NLE + HE = decrypt w/ wrong master password
gives realistic password vault

Supports machine generated random passwords

Domain privacy, easy online sync etc.<br>
slide29. Security of NoCrack Security goal: output of Decrypt should look “real”
Machine learning classifiers
Yahoo leak dataset, 50% attack success: Attacker will have to make many online queries<br>
slide30. Limitations/Future Work Side information about the victim might decrease online work significantly
Master password related to the passwords inside the vault
Website password restrictions
Improved attacks Note:
security never worse than
standard password-based encryption<br>
slide31. Summary We showed an effective attack against only prior work on decoy techniques. #KamouflageVulnerable

We devised a new mechanism to create decoys. #NaturalLanguageEncoder

Prototype of a Password Vault that utilizes NLE and HE, and offers most of the functionalities of modern password vaults. #NoCrack NoCrack Code and data available at:
https://pages.cs.wisc.edu/~rchat/projects/NoCrack.html<br>
slide32. Bibliography [1] H. Bojinov, E. Bursztein, X. Boyen, and D. Boneh, “Kamouflage: Loss-resistant password management,” in ESORICS, 2010

[2] Joseph Bonneau. The science of guessing: analyzing an anonymized corpus of 70 million passwords. In SP, 2012

[3] R. Veras, C. Collins, and J. Thorpe, “On the semantic patterns
of passwords and their security impact,” in NDSS, 2014.

[4] M. Weir, S. Aggarwal, B. de Medeiros, and B. Glodek, “Password cracking using probabilistic context-free grammars,” SP09, 2009

[5] A. Juels and T. Ristenpart, “Honey Encryption: Beyond the brute-force barrier,” in EUROCRYPT, 2014<br>
slide34. Issues with Kamouflage All master passwords share same template
Learning the template of the master password is N times more likely
After learning the template only try the passwords that matches the template
Replacements are selected with uniform probability
real master password is way more probable than decoys, needs very few online queries only.
Kamouflage+ also fails.<br>
slide35. Real But... WE FOUND A PROBLEM IN THE DECOY GENERATION family00
family01
family.1
qwerty poiuyt.12 W6D2
W6D21
W6S1D1
W61
W62S1D22 abcdef12
abcdef02
abcdef#1
thomas
temple#00 travis99
travis12
travis@7
soccer smiles@33 scooby33
scooby45
scooby!3
vanbus weiwei!69 W6D1 mypass4 .... { Decoys Templates All master passwords share the same template! violet9 zxcvbn9 shishi1<br>
slide36. Honey Encryption Plaintext mpw* Ciphertext mpw1 mpw2 mpw3 HE-Encrypt HE-Decrypt HE-Decrypt HE-Decrypt HE-Decrypt mpw2<br>
slide37. Decoy Technique 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Decryption
(Decoy) password
iloveyou pass4ever
iloveyou
password1 Vault Ciphertext Output of Decryption Attacker’s ordering
of master passwords 123456
password
iloveyou



mypass4
abc123
nicole
Daniel
.
.
. Decoy Vault<br>
slide38. Decoy Technique 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Decryption
(Decoy) letmein
treehouse letme1n
l3tmein!
tr33h0us3 Vault Ciphertext Output of Decryption Attacker’s ordering
of master passwords 123456
password
iloveyou



mypass4
abc123
nicole
Daniel
.
.
. Decoy Vault<br>
slide39. Decoy Technique 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… Decryption
(Decoy) Madona12
Madona12 123456
m@dona1 123456789 Vault Ciphertext Output of Decryption Attacker’s ordering
of master passwords 123456
password
iloveyou



mypass4
abc123
nicole
Daniel
.
.
. Decoy Vault<br>
slide40. Decoy Technique 0xe1f3f4a…
0x73bc52e…
0x4e5e373…
0x3c8b8ea…
0xe33188a… 123456
password
Iloveyou



mypass4
abc123
nicole
Daniel
.
.
. Decryption
(Decoy) family00
family01
family.1
qwerty
poiuyt.12 Vault Ciphertext Output of Decryption Attacker’s ordering
of master passwords Real Vault<br>
slide41. New Decoys Technique Honey Encryption by Juels and Ristenpart, EUROCRYPT 2014.
Decryption Never Fails!
Wrong pass  Decoy Text (fresh sample)
Cool Idea , But
needs an encoder to covert between uniform bit-string and plain text distribution
Showed for toy distribution.
For real distributions, it was left as an open problem.
We show how to build the encoder for Natural Languages, e.g., Password Vaults<br>
slide42. NLE for Single Password (using PCFG) Base PCFG
(this one was proposed by Weir et al., SP09)<br>
slide43. W8 password Password Model to NLE (using PCFG) We give ways to convert password sampler techniques to secure NLEs
n-gram
PCFG S Parse Tree of ‘password!’ decode(another random bit-string, PCFG):
a random parse tree and a random
password Y ! encode(‘family00’, PCFG) :
Encode every branch in the parse tree decode(random bit-string, PCFG) :
reconstruct the parse tree and
output the string it parses.<br>
slide44. NLE for Single Password (using PCFG) Encode a rule (e.g. S  W8 ):
choose a random number between [0.42, 0.51)<br>
slide45. NLE for Single Password (using PCFG) Decode a rule (e.g. S, 0.29):
/* Inverse Transform Sampling */
0.20≤ 0.29 < 0.32  W6D1<br>
slide46. NLE for Single Password (using PCFG) Encode( pw ):
Create a parse tree of the password in the base PCFG
Encode each rule in the parse tree
pad with random numbers (if needed) passwrod12 S  W8D2;
W8  ‘password’;
D2  ‘12’; 0.23,
0.12,
0.20,
0.13,
0.93,
…. Parse Tree Encoding<br>
slide47. NLE for Single Password (using PCFG) Decode ( list of bit-string ):
Decode each bit-string into rules and construct the parse tree from ‘S’ (stop when it is complete)
Get the string that is generated by the parse tree. passwrod12 S  W8D2;
W8  ‘password’;
D2  ‘12’; 0.23,
0.12,
0.20,
0.13,
0.93,
…. Parse Tree Encoding<br>
slide48. Evaluating Single Password NLE Classifiers for decoy and real passwords
Trained the Base PCFG with RY-tr leak (#Decoy)
Tested with RY-ts, MySpace , Yahoo leaks (#Real)
1-in-q experiment
Metric of Evaluation:
Accuracy of classification (α)
Rank-of-real based on classifier’s confidence (r)
Report average over all the passwords in each of the test leaks<br>
slide49. Results 100% 50% 60% 0% 50% 35% α r Rank-of-real Classification accuracy NLE using PCFG
(by Weir et al.) Best NLE Worst NLE Classifier thinks 35% of the decoy
passwords are more realistic than the real one!<br>
slide50. Evaluating Single Password NLE For best NLE α and r both should be close to 50%.
r denotes the amount of online work attacker has to do.<br>
slide51. NLE for Password Vault Sub-grammar PCFG
Hierarchical model (sort of)
Sample a sub-grammar
then sample passwords from the sub-grammar
How to sample a sub-grammar ?
a sub-grammar is again a set of rules
Sample rules from the base PCFG
Borrow the probabilities of each rule as well (for best results please normalize before use!)<br>
slide52. NLE for Password Vault Normalized Sub-grammar PCFG qwerty#1 ,
qwerty<1,
qwerty#3,
qwerty#12,
mywisc<3,
qwerty12,
…<br>
slide53. NLE for Password Vault Sub-grammar Real Normalized
Sub-grammar PCFG<br>
slide54. Evaluating Password Vault NLE Same setup except
with more feature vectors
Repeat Count
Edit distance
n-gram structure
Tested against: subset of Pastebin Vault leak (#Real)
Expected rank (r̅) > 37%.
At an average 37% of all the decoy vaults call for an online query!!
Online work = 37% of the Offline work<br>
slide55. : da#F7+wF4 NoCrack (A Password Manager with Honey Encryption) : family00
: family01
: family.1 google.com
facebook.com
my.wisc.edu
uwcu.org:john NoCrack
Server mymail@email.com<br>
slide56. Password Vaults (a.k.a Password Manager)<br>
slide57. Password Vaults (a.k.a Password Manager) Master Password: mypass4 Encrypted with a master password
Stored on the cloud for ease of accessibility<br>
slide58. Summary of Our Work Offline Brute-
Force Attack Weakness in only prior work Kamouflage NoCrack NLE<br>
slide59. Attacking Kamouflage Kamouflage
Vault Ciphertext Decryption
(Kamouflage) …

veronica
viper01
violet9 whatsup!
Wlidcat2
year2012
secret7


mypass4 ١ʇեर࢒ݠТ݈ր͖ृݩ̣ܔܢԳ঒̡̹ࢗ΄ݖऐख२࢓ձճʙЖ͇ـগउШɱ݀йԐգै̷ѡʂ̀ख़ SPEED UP!! Attacker’s ordering
of master password guesses Ignore the guesses that don’t match the template.<br>
slide60. NLE for Password Vault Password Vault
{John#1, John12, john123, John@123}

Independent samples from the base PCFG
{qwerty, john#1, password, wow1!}

Challenge:
How to model related passwords?
Sub-grammar Approach<br>
slide61. Security Evaluation for NLEs Security goal: output of Decode should look “real”
1-in-q experiment:
Attacker given list with 1 real and q-1 decoys generated by Decode
Can attacker “Sort the list” so that real is at top?
Best machine learning classifiers we found:
~35% of decoy passwords are perceived to be more real than the real one by our best classifier!
Ideal would be 50% Attacker will have to make many online queries<br>
slide62. Security Evaluation for NLEs Security goal: output of Decode should look “real”
Experimented with machine learning-based attacks
Best attack we could find:
q decryptions
q/3 online queries on average
Ideal security: q/2 online queries Attacker will have to make many online queries<br>