With the rapid development of internet technologies, social networks, and other related areas, user authentication becomes more and more important to protect the data of users. Password authentication is one of the widely used methods to achieve authentication for legal users and defense against intruders. There have been many password-cracking methods developed during the past years, and people have been designing countermeasures against password cracking all the time. However, we find that the survey work on password cracking research has not been done very much. This paper is mainly to give a brief review of the password cracking methods, import technologies of password cracking, and the countermeasures against password cracking that are usually designed at two stages including the password design stage (e.g. user education, dynamic password, use of tokens, computer generations) and after the design (e.g. reactive password checking, proactive password checking, password encryption, access control). The main objective of this work is to offer the abecedarian IT security professionals and the common audiences some knowledge about computer security and password cracking and promote the development of this area. Keywords- Computer security; User authentication; Password cracking; Cryptanalysis; Countermeasures
翻译:随着互联网技术、社交网络和其他相关领域的快速发展,用户认证对保护用户数据越来越重要。密码认证是广泛使用的一种方法,用于法律用户和防范入侵者,对法律用户进行认证和防范入侵者进行辩护。在过去几年中制定了许多密码破碎方法,人们一直在针对密码破解制定对策。然而,我们发现,密码破解研究的调查工作没有做很多。本文主要简要回顾密码破解方法、密码破解的进口技术以及通常在两个阶段设计的密码破解对策,包括密码设计阶段(例如用户教育、动态密码、标志的使用、计算机代)和设计之后(例如被动密码检查、主动密码检查、密码加密、访问控制)。这项工作的主要目的是向受忽视的信息技术安全专业人员和普通受众提供关于计算机安全和密码破解的一些知识,并促进这一领域的发展。关键词计算机安全;用户识别;密码破解;加密分析;反制;反制;反制。