Beyond 123456: Deciphering Password Vulnerabilities via Big Data Analytics

A password creation and validation system for social media platforms based on big data analytics

2019-01-22
Konstantinos F. Xylogiannopoulos, Panagiotis Karampelas, Reda Alhajj
Summary
Problem
Method
Results
Takeaways
Abstract

This paper introduces a novel password creation and validation system driven by big data analytics on leaked datasets. By utilizing a specialized "All Repeated Patterns Detection" (ARPaD) algorithm and LERP-RSA data structures, the methodology identifies both frequent and obscure character sequences to preemptively block weak passwords.

TL;DR

Researchers have developed a breakthrough system that moves beyond simple password rules (like "must include a symbol"). By using the ARPaD algorithm to mine millions of leaked passwords, the system identifies the "DNA" of weak passwords—the specific substrings people love to use—and blocks them in real-time. This method is computationally massive yet efficient, analyzing millions of patterns in minutes where previous methods took years.

The "Randomness" Illusion: Why Your Password Isn't Safe

The fundamental conflict in cybersecurity is Security vs. Memorability. When forced to meet complex requirements, humans don't become random; they become predictable. We use "LinkedIn123!" for LinkedIn or "P@ssword1" to satisfy the "one capital, one symbol" rule.

The authors argue that current password meters are lying to you. A password like aqwerty might be marked as unique because it doesn't appear in a standard dictionary, but it contains the highly frequent keyboard pattern qwerty.

Methodology: The Power of ARPaD and LERP-RSA

To catch these patterns, the authors didn't just look for words; they looked for substrings.

1. The Data Structure: LERP-RSA

They utilized the Longest Expected Repeated Pattern Reduced Suffix Array (LERP-RSA). Unlike traditional Suffix Arrays that can be memory-heavy, LERP-RSA uses a probabilistic approach to keep space complexity manageable while allowing for lightning-fast lexicographical sorting of every possible fragment of a password.

2. The Algorithm: ARPaD

The All Repeated Patterns Detection (ARPaD) algorithm then traverses this array to find every single repeated sequence across the entire dataset.

Algorithm Logic - LERP-RSA Construction Figure 1: Illustration of how suffix strings are truncated and sorted to identify repeated patterns efficiently.

Revolutionary Insights from the LinkedIn Leak

The team analyzed 5.6 million LinkedIn passwords. Their findings expose the "logic" of human password creation:

  • The Power of Substrings: Two passwords might look different, but share a 4-character substring like mama. This single piece of knowledge reduces brute-force cracking time by 10 billion times.
  • The "Area Code" Trap: The team found that "random" numbers like 212 appeared frequently. Why? It's the New York area code. Users frequently use phone numbers, believing their length (10+ digits) makes them strong.
  • Platform Mangling: Thousands of users on LinkedIn used the word linkedin or leet-speak versions like l1nk3d within their password.

Experimental Distribution of Password Lengths Figure 2: Distribution showing that while most passwords are ~9 characters, the patterns within them are the true indicators of weakness.

The Proposed System: PCVS

The proposed Password Creation and Validation System (PCVS) acts as a proactive shield.

  1. Real-time Analysis: As you type, the system breaks your password into LERP-RSA fragments.
  2. Frequency Check: It compares these fragments against a massive database of known patterns.
  3. Dynamic Blocking: If you type qwe..., the system immediately flags it as a weak prefix and suggests "lower frequency" substrings to increase entropy.

System Architecture Figure 3: The PCVS Architecture designed to integrate into existing social media registration flows.

Critical Analysis & Conclusion

Takeaway

The genius of this work lies in its efficiency. While n-gram analysis was historically too slow for long strings, the ARPaD approach makes deep pattern matching viable for production systems.

Limitations

The system relies on the availability of leaked datasets for "training" its pattern database. As attackers evolve, the system must constantly ingest new breaches to stay ahead of new human trends in password creation.

Future Outlook

This methodology could be extended to biometric template protection or automated honey-pot generation, where systems generate "believable" but fake user credentials to trap attackers.

Find Similar Papers

Try Our Examples

  • Search for recent papers that utilize Suffix Arrays or Suffix Trees for proactive password strength estimation and real-time validation.
  • What is the definitive paper for the ARPaD algorithm (All Repeated Patterns Detection), and how has it been optimized for distributed big data environments since 2014?
  • Are there studies exploring the application of Big Data pattern detection in identifying compromised credentials in Multi-Factor Authentication (MFA) or biometric salt generation?
Contents
Beyond 123456: Deciphering Password Vulnerabilities via Big Data Analytics
1. TL;DR
2. The "Randomness" Illusion: Why Your Password Isn't Safe
3. Methodology: The Power of ARPaD and LERP-RSA
3.1. 1. The Data Structure: LERP-RSA
3.2. 2. The Algorithm: ARPaD
4. Revolutionary Insights from the LinkedIn Leak
5. The Proposed System: PCVS
6. Critical Analysis & Conclusion
6.1. Takeaway
6.2. Limitations
6.3. Future Outlook