Password Pattern and Vulnerability Analysis for Web and Mobile Applications

Release Date:2016-07-15 Author:LI Shancang, Imed Romdhani, and William Buchanan Click:

[Abstract] Text⁃based passwords are heavily used to defense for many web and mobile applications. In this paper, we investigated the patterns and vulnerabilities for both web and mobile applications based on conditions of the Shannon entropy, Guessing entropy and Minimum entropy. We show how to substantially improve upon the strength of passwords based on the analysis of text⁃password entropies. By analyzing the passwords datasets of Rockyou and 163.com, we believe strong password can be designed based on good usability, deployability, rememberbility, and security entropies.

[Keywords] password strength; security entropies; password vulnerabilities

Download: PDF