Cipher-Guard: A Machine Learning Model for Adaptive and Context-Aware Password Security

IF 2 4区 计算机科学 Q3 COMPUTER SCIENCE, INFORMATION SYSTEMS
Mohammed Naif Alatawi
{"title":"Cipher-Guard: A Machine Learning Model for Adaptive and Context-Aware Password Security","authors":"Mohammed Naif Alatawi","doi":"10.1049/ise2/3930060","DOIUrl":null,"url":null,"abstract":"<p>This research aims to enhance password security by designing, training and testing Cipher-Guard, a machine learning (ML) algorithm that incorporates complex features and techniques derived from proven feature engineering. The current model is inherently built on the equations of mathematical modelling concerning complexity metrics of passwords and contextualisation. This is in terms of password length (PL), entropy (<i>E</i>) and the character set diversity (CSD) of the passwords, as well as contextual embeddings such as user-specific password history (UPH) and temporal patterns (TPs). A simulation of the data matrix was created, containing 1000 records, which formed the basis of the model and a thorough exploratory data analysis (EDA). The proposed model demonstrates interpretability and credibility in distinguishing patterns related to password complexity metrics, yielding promising formative results in the specified evaluation metrics. PL, <i>E</i> and CSD were analysed thoroughly, and the importance of increasing password security was identified. Specific contextual embeddings were identified as UPH and TPs, which reflect the model’s ability to adapt to the particular user’s actions. Including adversarial training features also helped protect the model from potential manipulations through a proactive defence plan. Moreover, the enhancement of cryptographic principles, which include hashing and salting, also improved the dataset security, thereby increasing the standard practice within the industry. The metrics involved in the comparative assessment included receiver operating characteristic-area under the curve (ROC-AUC), learning curves, confusion matrix, precision matrix and precision-recall curves, among others. Cipher-Guard performed consistently well across these parameters, which has reinforced its authenticity in strengthening password protection. However, to appreciate such findings, certain constraints need to be well addressed, such as the quality of the chosen dataset, some ethical concerns raised in the study and the fact that new threats are constantly emerging. Recommendations for enhancing continuous dataset monitoring and establishing an ethical framework for the case are also suggested. The research directions broaden future possibilities for research while emphasising continuous model updating, individual-centred protection and compatibility with other emerging technologies. Therefore, Cipher-Guard represents a significant advancement in password protection and offers a promising prospect for flexible and personalised security in the modern era.</p>","PeriodicalId":50380,"journal":{"name":"IET Information Security","volume":"2026 1","pages":""},"PeriodicalIF":2.0000,"publicationDate":"2026-06-19","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://onlinelibrary.wiley.com/doi/epdf/10.1049/ise2/3930060","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"IET Information Security","FirstCategoryId":"94","ListUrlMain":"https://onlinelibrary.wiley.com/doi/10.1049/ise2/3930060","RegionNum":4,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q3","JCRName":"COMPUTER SCIENCE, INFORMATION SYSTEMS","Score":null,"Total":0}
引用次数: 0

Abstract

This research aims to enhance password security by designing, training and testing Cipher-Guard, a machine learning (ML) algorithm that incorporates complex features and techniques derived from proven feature engineering. The current model is inherently built on the equations of mathematical modelling concerning complexity metrics of passwords and contextualisation. This is in terms of password length (PL), entropy (E) and the character set diversity (CSD) of the passwords, as well as contextual embeddings such as user-specific password history (UPH) and temporal patterns (TPs). A simulation of the data matrix was created, containing 1000 records, which formed the basis of the model and a thorough exploratory data analysis (EDA). The proposed model demonstrates interpretability and credibility in distinguishing patterns related to password complexity metrics, yielding promising formative results in the specified evaluation metrics. PL, E and CSD were analysed thoroughly, and the importance of increasing password security was identified. Specific contextual embeddings were identified as UPH and TPs, which reflect the model’s ability to adapt to the particular user’s actions. Including adversarial training features also helped protect the model from potential manipulations through a proactive defence plan. Moreover, the enhancement of cryptographic principles, which include hashing and salting, also improved the dataset security, thereby increasing the standard practice within the industry. The metrics involved in the comparative assessment included receiver operating characteristic-area under the curve (ROC-AUC), learning curves, confusion matrix, precision matrix and precision-recall curves, among others. Cipher-Guard performed consistently well across these parameters, which has reinforced its authenticity in strengthening password protection. However, to appreciate such findings, certain constraints need to be well addressed, such as the quality of the chosen dataset, some ethical concerns raised in the study and the fact that new threats are constantly emerging. Recommendations for enhancing continuous dataset monitoring and establishing an ethical framework for the case are also suggested. The research directions broaden future possibilities for research while emphasising continuous model updating, individual-centred protection and compatibility with other emerging technologies. Therefore, Cipher-Guard represents a significant advancement in password protection and offers a promising prospect for flexible and personalised security in the modern era.

Abstract Image

Cipher-Guard:用于自适应和上下文感知密码安全的机器学习模型
本研究旨在通过设计,培训和测试Cipher-Guard来提高密码安全性,Cipher-Guard是一种机器学习(ML)算法,它结合了复杂的特征和源自成熟特征工程的技术。当前的模型本质上是建立在关于密码和上下文化的复杂性度量的数学建模方程上的。这是指密码长度(PL)、熵(E)和密码的字符集多样性(CSD),以及上下文嵌入,如用户特定的密码历史(UPH)和时间模式(tp)。创建了一个包含1000条记录的数据矩阵模拟,这些记录构成了模型和全面探索性数据分析(EDA)的基础。所提出的模型在区分与密码复杂性度量相关的模式方面证明了可解释性和可信性,在指定的评估度量中产生了有希望的形成性结果。深入分析了PL, E和CSD,并确定了提高密码安全性的重要性。特定的上下文嵌入被确定为UPH和tp,它们反映了模型适应特定用户行为的能力。包括对抗性训练特征也有助于通过主动防御计划保护模型免受潜在的操纵。此外,加密原理的增强,包括散列和盐化,也提高了数据集的安全性,从而增加了行业内的标准实践。比较评价指标包括受试者工作特征曲线下面积(ROC-AUC)、学习曲线、混淆矩阵、精度矩阵和精密度-召回率曲线等。Cipher-Guard在这些参数中表现一致,这增强了它在加强密码保护方面的真实性。然而,要欣赏这些发现,需要很好地解决某些限制,例如所选数据集的质量,研究中提出的一些伦理问题以及新威胁不断出现的事实。本文还提出了加强连续数据集监测和建立案例伦理框架的建议。研究方向拓宽了未来研究的可能性,同时强调持续的模型更新,以个人为中心的保护以及与其他新兴技术的兼容性。因此,Cipher-Guard代表了密码保护的重大进步,为现代灵活个性化的安全提供了广阔的前景。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
IET Information Security
IET Information Security 工程技术-计算机:理论方法
CiteScore
3.80
自引率
7.10%
发文量
47
审稿时长
8.6 months
期刊介绍: IET Information Security publishes original research papers in the following areas of information security and cryptography. Submitting authors should specify clearly in their covering statement the area into which their paper falls. Scope: Access Control and Database Security Ad-Hoc Network Aspects Anonymity and E-Voting Authentication Block Ciphers and Hash Functions Blockchain, Bitcoin (Technical aspects only) Broadcast Encryption and Traitor Tracing Combinatorial Aspects Covert Channels and Information Flow Critical Infrastructures Cryptanalysis Dependability Digital Rights Management Digital Signature Schemes Digital Steganography Economic Aspects of Information Security Elliptic Curve Cryptography and Number Theory Embedded Systems Aspects Embedded Systems Security and Forensics Financial Cryptography Firewall Security Formal Methods and Security Verification Human Aspects Information Warfare and Survivability Intrusion Detection Java and XML Security Key Distribution Key Management Malware Multi-Party Computation and Threshold Cryptography Peer-to-peer Security PKIs Public-Key and Hybrid Encryption Quantum Cryptography Risks of using Computers Robust Networks Secret Sharing Secure Electronic Commerce Software Obfuscation Stream Ciphers Trust Models Watermarking and Fingerprinting Special Issues. Current Call for Papers: Security on Mobile and IoT devices - https://digital-library.theiet.org/files/IET_IFS_SMID_CFP.pdf
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信
小红书