Chuanwang Wang

dblp:275/3599 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2023
0000-0002-6764-9184ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 5 since 2021
YearPublicationVenuePosition
2023 Improving Real-world Password Guessing Attacks via Bi-directional Transformers
Ming Xu 0006, Jitao Yu, Chuanwang Wang, Haoqi Wu, Weili Han
USENIX Security Symposium4
2022 #Segments: A Dominant Factor of Password Security to Resist against Data-driven Guessing
Chuanwang Wang, Ming Xu 0006, Weili Han
Comput. Secur.1
2021 Digit Semantics based Optimization for Practical Password Cracking Tools
abstract
Users usually create their passwords with meaningful digits, i.e. digit semantics, which can be partially exploited by probabilistic password guessing models with a data-driven methodology for better efficiency. However, these semantics are largely ignored by current practical password cracking tools, like John the Ripper (JtR) and Hashcat.
Chuanwang Wang, Wenqiang Ruan, Ming Xu 0006, Weili Han
ACSAC2
2021 Chunk-Level Password Guessing: Towards Modeling Refined Password Composition Representations
abstract
Textual password security hinges on the guessing models adopted by attackers, in which a suitable password composition representation is an influential factor. Unfortunately, the conventional models roughly regard a password as a sequence of characters, or natural-language-based words, which are password-irrelevant. Experience shows that passwords exhibit internal and refined patterns, e.g., "4ever, ing or 2015", varying significantly among periods and regions. However, the refined representations and their security impacts could not be automatically understood by state-of-the-art guessing models (e.g., Markov).
Ming Xu 0006, Chuanwang Wang, Jitao Yu, Kai Zhang 0006, Weili Han
CCS2
2021 TransPCFG: Transferring the Grammars From Short Passwords to Guess Long Passwords Effectively
abstract
Long passwords are gaining popularity in password policy recommendations; however, data-driven guessing studies are woefully inadequate in adapting to long passwords, lacking in both guessing efficiency and their composition guidelines. For state-of-the-art data-driven password guessing methods such as PCFGs (Probabilistic Context-free Grammars), their guessing efficiency is limited by the presence of a large scale training data, or the lack thereof. Given that long passwords leaked in the real world are typically scarce, coupled with the fact that the data-driven methods’ performance depends on training data, obtaining good performance on long passwords has become a key challenge. To overcome the dataset limitation, we propose a frameworkTransPCFG, that transfers the knowledge, (i.e., grammars in PCFGs), from short passwords to facilitate long password guessing. We further perform an empirical evaluation based on three real-world datasets and the results demonstrate superior performance over the state-of-the-art data-driven guessing methods under${10}^{14}$offline guesses. For passwords with 16 characters,TransPCFGcan compromise an average of 23.30% of the passwords, outperforming PCFG_v4.1 by 56.10%. Additionally,for better password-composition guidelines, we find that long password-composition policies requiring more segments are more resistant to guessing attacks. For the segment, the password12zxcvbnword1997has four segments since it follows the template${Digit}_{2}{Keyboard}_{6}{Letter}_{4}{Year}_{4}$. We thus recommend users to create long passwords with four or more segments instead of the widely recommended more character classes for security.
Weili Han, Ming Xu 0006, Chuanwang Wang, Kai Zhang 0006, Xiaoyang Sean Wang
IEEE Trans. Inf. Forensics Secur.4