使用长期蜜罐数据跟踪密码泄露的流行程度

Jianzhou You, Bozhong Liu, Yang Wang, Laiyoumei Jiang
{"title":"使用长期蜜罐数据跟踪密码泄露的流行程度","authors":"Jianzhou You, Bozhong Liu, Yang Wang, Laiyoumei Jiang","doi":"10.1117/12.2682267","DOIUrl":null,"url":null,"abstract":"Passwords are critical issues in the world of cyber security. Unfortunately, despite best efforts, passwords continue to be compromised and leaked onto the Internet, leading to an alarming number of compromised passwords in circulation. In this study, we compare honeypot-captured data from 2021 and 2023 to measure the prevalence of compromised passwords in real-world cyberattacks. Specially, we designed and deployed an online SSH honeypot on the cloud server to capture the latest cyber intelligence in the wild. Our findings show that over 90% of brute force attacks involve the use of compromised passwords, indicating a high level of password vulnerability. Additionally, we observe that the effectiveness of strong-password policies in mitigating such attacks appears limited. This study highlights the need for better password security strategies to counter the high prevalence of compromised passwords in cyberattacks.","PeriodicalId":177416,"journal":{"name":"Conference on Electronic Information Engineering and Data Processing","volume":"32 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2023-05-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Tracking the prevalence of compromised passwords using long-term honeypot data\",\"authors\":\"Jianzhou You, Bozhong Liu, Yang Wang, Laiyoumei Jiang\",\"doi\":\"10.1117/12.2682267\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Passwords are critical issues in the world of cyber security. Unfortunately, despite best efforts, passwords continue to be compromised and leaked onto the Internet, leading to an alarming number of compromised passwords in circulation. In this study, we compare honeypot-captured data from 2021 and 2023 to measure the prevalence of compromised passwords in real-world cyberattacks. Specially, we designed and deployed an online SSH honeypot on the cloud server to capture the latest cyber intelligence in the wild. Our findings show that over 90% of brute force attacks involve the use of compromised passwords, indicating a high level of password vulnerability. Additionally, we observe that the effectiveness of strong-password policies in mitigating such attacks appears limited. This study highlights the need for better password security strategies to counter the high prevalence of compromised passwords in cyberattacks.\",\"PeriodicalId\":177416,\"journal\":{\"name\":\"Conference on Electronic Information Engineering and Data Processing\",\"volume\":\"32 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2023-05-26\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Conference on Electronic Information Engineering and Data Processing\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1117/12.2682267\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Conference on Electronic Information Engineering and Data Processing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1117/12.2682267","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

密码是网络安全领域的关键问题。不幸的是,尽管尽了最大的努力,密码仍然被泄露并泄露到互联网上,导致大量被泄露的密码在流通。在本研究中,我们比较了2021年和2023年的蜜罐捕获数据,以衡量现实世界网络攻击中密码泄露的普遍程度。特别地,我们在云服务器上设计并部署了一个在线SSH蜜罐,以捕获野外最新的网络智能。我们的研究结果表明,超过90%的暴力攻击涉及使用受损的密码,这表明密码存在很高的漏洞。此外,我们观察到强密码策略在减轻此类攻击方面的有效性似乎有限。这项研究强调了更好的密码安全策略的必要性,以应对网络攻击中密码泄露的高发性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Tracking the prevalence of compromised passwords using long-term honeypot data
Passwords are critical issues in the world of cyber security. Unfortunately, despite best efforts, passwords continue to be compromised and leaked onto the Internet, leading to an alarming number of compromised passwords in circulation. In this study, we compare honeypot-captured data from 2021 and 2023 to measure the prevalence of compromised passwords in real-world cyberattacks. Specially, we designed and deployed an online SSH honeypot on the cloud server to capture the latest cyber intelligence in the wild. Our findings show that over 90% of brute force attacks involve the use of compromised passwords, indicating a high level of password vulnerability. Additionally, we observe that the effectiveness of strong-password policies in mitigating such attacks appears limited. This study highlights the need for better password security strategies to counter the high prevalence of compromised passwords in cyberattacks.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信