Achieving Flatness Selecting Honeywords From Existing User Passwords
Loading...
Files
Date
2017-08-16T06:58:10Z
Authors
Journal Title
Journal ISSN
Volume Title
Publisher
Abstract
Recently, proposed honey words (decoy passwords) to detect attacks against hashed
password databases. For each user account, the legitimate password is stored with several
honey words in order to sense impersonation. If honey words are selected properly, a
cyber-attacker who steals a file of hashed passwords cannot be sure if it is the real
password or a honey word for any account. Moreover, entering with a honey word to
login will trigger an alarm notifying the administrator about a password file breach. At
the expense of increasing the storage requirement by 20 times, the authors introduce a
simple and effective solution to the detection of password file disclosure events. In this
study, we scrutinize the honey word system and present some remarks to highlight
possible weak points. Also, we suggest an alternative approach that selects the honey
words from existing user passwords in the system in order to provide realistic honey
words – a perfectly flat honey word generation method – and also to reduce storage cost
of the honey word scheme.
Description
Keywords
Sushmitha Jain, Satwika P, Sushmitha Jain, Achieving Flatness Selecting Honeywords From Existing User Passwords