Jitao Yu

dblp:306/0786 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 since 2021
YearPublicationVenuePosition
2025 On the Account Security Risks Posed by Password Strength Meters
Ming Xu 0006, Weili Han, Jitao Yu, Yun Lin 0001, Jin Song Dong 0001
AsiaCCS3
2025 Using Parallel Techniques to Accelerate PCFG-Based Password Cracking Attacks
abstract
Textual passwords play an important role among access-control mechanisms and are usually stored as ciphertext in the server. However, an attacker may attempt to hash a large number of candidate passwords to find the match of the target hash of a password database. To crack the password database, attackers in industry usually use the cracking software like Hashcat. Academic researchers recently proposed many data-driven probabilistic models, in which the Probabilistic Context-free Grammars (PCFG, for short) stand out. Despite the great cracking efficiency, the data-driven models are seldom used by industrial practice due to the significant slow generation speed of password candidates. To bridge the gap and promote the efficient data-driven models being practically used in industry, we propose that using parallel techniques to accelerate the candidate password generation, enabling the integration of PCFG models into the practically-used Hashcat tool. To this end, we mainly propose two algorithms to accelerate the password generation for PCFG-based models: first, we design a storage structure with the memory load balance strategy to more evenly store the data structures used to generate passwords; second, we design an algorithm to produce candidate passwords in parallel by different threads. Based on the two algorithms, we proposeParallel_PCFG, and implementParallel_PCFGupon Hashcat based on its built-in GPU kernel. We comprehensively evaluateParallel_PCFGagainst state-of-the-art data-driven models, and find thatParallel_PCFGonly takes 14.33% of time to achieve the same cracking rates compared with the best-performing models, paving a way about the integration between PCFG-based models and Hashcat.
Ming Xu 0006, Kai Zhang 0006, Jitao Yu, Luwei Cheng, Weili Han
IEEE Trans. Dependable Secur. Comput.6
2023 Improving Real-world Password Guessing Attacks via Bi-directional Transformers
Ming Xu 0006, Jitao Yu, Chuanwang Wang, Haoqi Wu, Weili Han
USENIX Security Symposium2
2021 Chunk-Level Password Guessing: Towards Modeling Refined Password Composition Representations
abstract
Textual password security hinges on the guessing models adopted by attackers, in which a suitable password composition representation is an influential factor. Unfortunately, the conventional models roughly regard a password as a sequence of characters, or natural-language-based words, which are password-irrelevant. Experience shows that passwords exhibit internal and refined patterns, e.g., "4ever, ing or 2015", varying significantly among periods and regions. However, the refined representations and their security impacts could not be automatically understood by state-of-the-art guessing models (e.g., Markov).
Ming Xu 0006, Chuanwang Wang, Jitao Yu, Kai Zhang 0006, Weili Han
CCS3