Modeling and Information System in Economics
Кількісна оцінка стійкості паролів у системах автентифікації на основі ентропійних та ймовірнісних моделей
Quantitative evaluation of password strength in authentication systems based on entropy and probabilistic models
10.33111/mise.105.12
# 105 / 2025
1. Bonneau J., Herley C., van Oorschot P. C., Stajano F. Passwords and the Evolution of Imperfect Authentication. Communications of the ACM. 2015. Vol. 58, No. 7. P. 78–87.
2. Kelley P. G., Komanduri S., et al. Guess Again (and Again and Again): Measuring Password Strength by Simulating Password-Cracking Algorithms. 2012 IEEE Symposium on Security and Privacy. 2012. P. 523–537.
3. Ma J., Yang W., Luo M., Li N. A Study of Probabilistic Password Models. 2014 IEEE Symposium on Security and Privacy. 2014. P. 689–704.
4. Massey J. L. Guessing and entropy. Proceedings of 1994 IEEE International Symposium on Information Theory. 1994. P. 204. 156
5. DellʼAmico M., Michiardi P., Roudier Y. Password Strength: An Empirical Analysis. INFOCOM, 2010 Proceedings IEEE. 2010. P. 1–9.
7. Castelluccia C., Dürmuth M., Perito D. Adaptive Password-Strength Meters from Markov Models. Proceedings of the 19th NDSS. 2012.
8. Pliam J. O. The Disparity between Work and Entropy in Cryptology. IACR Cryptology ePrint Archive. 1998. Report 1998/024.
9. Shannon C. E. A Mathematical Theory of Communication. Bell System Technical Journal. 1948. Vol. 27.
10. Reaz K., Wunder G. Expectation Entropy as a Password Strength Metric. arXiv preprint arXiv:2404.16853. 2024.
11. Wheeler D. L. zxcvbn: Low-Budget Password Strength Estimation. 25th USENIX Security Symposium. 2016. P. 157–173.
12. Weir M. et al. Password Cracking Using Probabilistic Context-Free Grammars. 2009 IEEE Symposium on Security and Privacy. 2009. P. 391 405.

