Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Zhenhan Li

dblp:271/9694 · DBLP profile ↗
← Back
3ranked-venue papers
0as first author
1since 2021 · last 2024
0000-0001-6347-2767ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 since 2021Computer networks · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Authentication and access control · 100%

Topics — the 2 heaviest of 2, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control › knowledge-based authentication
password
0.812024
GuessFuse: Hybrid Password Guessing With Multi-View · IEEE Trans. Inf. Forensics Secur. 2024
Authentication and access control
password guessing
0.812024
GuessFuse: Hybrid Password Guessing With Multi-View · IEEE Trans. Inf. Forensics Secur. 2024

Methods — techniques the papers use, named apart from their topics

multi-view learning · 0.8
YearPublicationVenuePosition
2024 GuessFuse: Hybrid Password Guessing With Multi-View
abstract
Password guessing is a primary method for password strength evaluation. Despite various password guessing models have been proposed, there is still a significant gap between their guessing effectiveness and the actual cracking capabilities of attackers. Integrating multiple models for password guessing, also known as hybrid password guessing, could better capture the cracking capabilities of real attackers. However, the reason why hybrid password guessing can enhance cracking capabilities, and how to effectively integrate multiple heterogeneous password guessing models, are still not well understood. To address these issues, this paper draws inspiration from the concept of multi-view learning. We regard the guess lists generated by various password guessing models as multiple views of the data. Through a comprehensive analysis of these guess lists, we have identified the key reason why hybrid password guessing can enhance the cracking capabilities: integrating more diverse views allows for the coverage of a wider range of heterogeneous password characteristics, and provides more detailed information on effective password distributions. Based on the these findings, we propose a new hybrid password guessing framework, namedGuessFuse.GuessFuseemploys the multi-view subset extraction module and segment splitting selection module to accurately extract and reorganize the effective password from multiple guess lists. Experimental results on six large-scale datasets demonstrate the effectiveness ofGuessFuse. By combining two (resp. five) guess lists,GuessFuseoutperforms its foremost counterparts by an average of 11.00% ~ 59.62% (resp. 4.70% ~ 17.66%) within 107guesses.GuessFusecan effectively improve the cracking success rate under a limited number of guesses, approaching the actual cracking capabilities of attackers.
Zhijie Xie, Fan Shi 0003, Min Zhang 0054, Huimin Ma 0004, Huaixi Wang, Zhenhan Li
IEEE Trans. Inf. Forensics Secur.6
2020 A New Targeted Password Guessing Model
Zhijie Xie, Anqi Yin, Zhenhan Li
ACISP4
2020 Modified Password Guessing Methods Based on TarGuess-I
abstract
TarGuess − I is a leading online targeted password guessing model using users’ personally identifiable information (PII) proposed at ACM CCS 2016 by Wang et al. It has attracted widespread attention in password security owing to its superior guessing performance. Yet, after analyzing the users’ vulnerable behaviors of using popular passwords and constructing passwords with users’ PII, we find that this model does not take into account popular passwords, keyboard patterns, and the special strings. The special strings are the strings related to users but do not appear in the users’ demographic information. Thus, we propose TarGuess − I + K P X , a modified password guessing model with three semantic methods, including (1) identifying popular passwords by generating top-300 lists from similar websites, (2) recognizing keyboard patterns by relative position, and (3) catching the special strings by extracting continuous characters from user-generated PII. We conduct a series of evaluations on six large-scale real-world leaked password datasets. The experimental results show that our modified model outperforms TarGuess − I by 2.62% within 100 guesses.
Zhijie Xie, Min Zhang 0054, Yuqi Guo 0002, Zhenhan Li, Hongjun Wang 0010
Wirel. Commun. Mob. Comput.4