Achieving Flatness Selecting Honeywords From Existing User Passwords

Loading...
Thumbnail Image
Files
Date
2017-08-16T06:58:10Z
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Recently, proposed honey words (decoy passwords) to detect attacks against hashed password databases. For each user account, the legitimate password is stored with several honey words in order to sense impersonation. If honey words are selected properly, a cyber-attacker who steals a file of hashed passwords cannot be sure if it is the real password or a honey word for any account. Moreover, entering with a honey word to login will trigger an alarm notifying the administrator about a password file breach. At the expense of increasing the storage requirement by 20 times, the authors introduce a simple and effective solution to the detection of password file disclosure events. In this study, we scrutinize the honey word system and present some remarks to highlight possible weak points. Also, we suggest an alternative approach that selects the honey words from existing user passwords in the system in order to provide realistic honey words – a perfectly flat honey word generation method – and also to reduce storage cost of the honey word scheme.
Description
Keywords
Sushmitha Jain, Satwika P, Sushmitha Jain, Achieving Flatness Selecting Honeywords From Existing User Passwords
Citation
Collections