(Press-News.org) PITTSBURGH—When writing or speaking, good grammar helps people make themselves be understood. But when used to concoct a long computer password, grammar — good or bad — provides crucial hints that can help someone crack that password, researchers at Carnegie Mellon University have demonstrated.
A team led by Ashwini Rao, a software engineering Ph.D. student in the Institute for Software Research, developed a password-cracking algorithm that took into account grammar and tested it against 1,434 passwords containing 16 or more characters. The grammar-aware cracker surpassed other state-of-the-art password crackers when passwords had grammatical structures, with 10 percent of the dataset cracked exclusively by the team's algorithm.
"We should not blindly rely on the number of words or characters in a password as a measure of its security," Rao concluded. She will present the findings on Feb. 20 at the Association for Computing Machinery's Conference on Data and Application Security and Privacy (CODASPY 2013) in San Antonio, Texas.
Basing a password on a phrase or short sentence makes it easier for a user to remember, but the grammatical structure dramatically narrows the possible combinations and sequences of words, she noted.
Likewise, grammar, whether good or bad, necessitates using different parts of speech — nouns, verbs, adjectives, pronouns — that also can undermine security. That's because pronouns are far fewer in number than verbs, verbs fewer than adjectives and adjectives fewer than nouns. So a password composed of "pronoun-verb-adjective-noun," such as "Shehave3cats" is inherently easier to decode than "Andyhave3cats," which follows "noun-verb-adjective-noun." A password that incorporated more nouns would be even more secure.
"I've seen password policies that say, 'Use five words,'" Rao said. "Well, if four of those words are pronouns, they don't add much security."
For instance, the team found that the five-word passphrase "Th3r3 can only b3 #1!" was easier to guess than the three-word passphrase "Hammered asinine requirements." Neither the number of words nor the number of characters determined password strength when grammar was involved. The researchers calculated that "My passw0rd is $uper str0ng!" is 100 times stronger as a passphrase than "Superman is $uper str0ng!," which in turn is 10,000 times stronger than "Th3r3 can only b3 #1!"
The research was an outgrowth of a class project for a masters-level course at CMU, Rao said. She and Gananand Kini, a fellow CMU graduate student, and Birendra Jha, a Ph.D. student at MIT, built their password cracker by building a dictionary for each part of speech and identifying a set of grammatical sequences, such as "determiner-adjective-noun" and "noun-verb-adjective-adverb," that might be used to generate passphrases.
Rao said the grammar-aware password cracker was intended only as a proof of concept and no attempt has been made to optimize its performance. But it is only a matter of time before someone does, she predicted.
###
The Institute for Software Research is part of CMU's School of Computer Science. Follow the school on Twitter @SCSatCMU.
About Carnegie Mellon University: Carnegie Mellon (www.cmu.edu) is a private, internationally ranked research university with programs in areas ranging from science, technology and business, to public policy, the humanities and the arts. More than 11,000 students in the university's seven schools and colleges benefit from a small student-to-faculty ratio and an education characterized by its focus on creating and implementing solutions for real problems, interdisciplinary collaboration and innovation. A global university, Carnegie Mellon's main campus in the United States is in Pittsburgh, Pa. It has campuses in California's Silicon Valley and Qatar, and programs in Africa, Asia, Australia, Europe and Mexico. The university is in the midst of "Inspire Innovation: The Campaign for Carnegie Mellon University," which aims to build its endowment, support faculty, students and innovative research, and enhance the physical campus with equipment and facility improvements.
Grammar undercuts security of long computer passwords
Carnegie Mellon researchers devise grammar-aware password cracker
2013-01-24
ELSE PRESS RELEASES FROM THIS DATE:
Neuroinflammation may be behind general-anesthesia-associated learning disabilities
2013-01-24
Several studies have found evidence that children who undergo repeated surgical operations with general anesthesia before the age of 4 may be at an increased risk for learning disabilities. In the March issue of Anesthesiology, Massachusetts General Hospital (MGH) researchers report an animal study indicating that several factors – age, the specific anesthetic agent used and the number of doses – combine to induce impairments in learning and memory accompanied by the inflammation of brain tissue. An accompanying paper from the same team finds that the offspring of mice ...
Urban metabolism for the urban century
2013-01-24
New Haven, Conn.–Like organisms, cities need energy, water, and nutrients, and they need to dispose of wastes and byproducts in ways that are viable and sustainable over the long run. This notion of "urban metabolism" is a model for looking systematically at the resources that flow into cities and the wastes and emissions that flow out from them—to understand the environmental impacts of cities and to highlight opportunities for efficiencies, improvements, and transformation.
Yale University's Journal of Industrial Ecology is pleased to announce a special issue on Sustainable ...
New dinosaur fossil challenges bird evolution theory
2013-01-24
The discovery of a new bird-like dinosaur from the Jurassic period challenges widely accepted theories on the origin of flight.
Co-authored by Dr Gareth Dyke, Senior Lecturer in Vertebrate Palaeontology at the University of Southampton, the paper describes a new feathered dinosaur about 30 cm in length which pre-dates bird-like dinosaurs that birds were long thought to have evolved from.
Over many years, it has become accepted among palaeontologists that birds evolved from a group of dinosaurs called theropods from the Early Cretaceous period of Earth's history, around ...
Sun shoots out 2 coronal mass ejections
2013-01-24
VIDEO:
This movie shows two coronal mass ejections (CMEs) erupting from the sun on Jan. 23, 2013. The first was not directed at Earth; the second one is, but is not...
Click here for more information.
On Jan. 23, 2013, at 9:55 a.m. EST, the sun erupted with an Earth-directed coronal mass ejection, or CME. Experimental NASA research models, based on observations from the Solar Terrestrial Relations Observatory (STEREO) and ESA/NASA's Solar and Heliospheric Observatory, show ...
Valuing nature is not enough
2013-01-24
Is it possible to put a price tag on the natural world? A researcher at The University of Nottingham has been examining the rise of a new concept — ecosystem services — to describe the multitude of resources supplied to us by Mother Nature.
Academic Dr Marion Potschin, of the University's Centre for Environmental Management, is among an international team of researchers who have been investigating the ethical considerations of this new concept, which some have argued turns nature into a 'commodity'.
In a paper published in the journal BioScience, Dr Potschin and her ...
Cells 'flock' to heal wounds
2013-01-24
Like flocks of birds, cells coordinate their motions as they race to cover and ultimately heal wounds to the skin. How that happens is a little less of a mystery today.
Researchers once thought only the cells at the edge of a growing patch of wounded skin were actively moving while dividing cells passively filled in the middle. But that's only part of the picture. Rice University physicist Herbert Levine and his colleagues have discovered that the process works much more efficiently if highly activated cells in every part of the patch exert force as they pull their neighbors ...
UCI neuroscientists create fiber-optic method of arresting epileptic seizures
2013-01-24
Irvine, Calif., Jan. 24, 2013 — UC Irvine neuroscientists have developed a way to stop epileptic seizures with fiber-optic light signals, heralding a novel opportunity to treat the most severe manifestations of the brain disorder.
Using a mouse model of temporal lobe epilepsy, Ivan Soltesz, Chancellor's Professor and chair of anatomy & neurobiology, and colleagues created an EEG-based computer system that activates hair-thin optical strands implanted in the brain when it detects a real-time seizure.
These fibers subsequently "turn on" specially expressed, light-sensitive ...
Mouse menopause model sheds light on UTIs in post-menopausal women
2013-01-24
Researchers from Washington University School of Medicine, St. Louis, show that reservoirs of uropathogenic E. coli within the bladder exist in higher numbers post-menopause than pre-menopause in a mouse model, a finding that could help explain the greater prevalence of urinary tract infections in post-menopausal women. They also found that estrogen supplementation reduced the numbers of such reservoirs dramatically. The research was published online ahead of print in the journal Infection and Immunity.
Urinary tract infections (UTIs) afflict an estimated 13 million ...
Vocabulary instruction failing US students
2013-01-24
EAST LANSING, Mich. — Vocabulary instruction in the early years is not challenging enough to prepare students for long-term reading comprehension, argues a study led by a Michigan State University education researcher.
The study, which appears in Elementary School Journal, analyzed commonly used reading curricula in U.S. kindergarten classrooms. It found that, generally, the programs do not teach enough vocabulary words; the words aren't challenging enough; and not enough focus is given to make sure students understand the meaning of the words.
"Vocabulary instruction ...
Research: Lupus drugs carry no significant cancer risk for patients
2013-01-24
This press release is available in French.
Montreal, January 24, 2013 – People who take immunosuppressive drugs to treat lupus do not necessarily increase their cancer risk according to new research led by scientists at the Research Institute of the McGill University Health Centre (RI-MUHC). This landmark study, which was published in Annals of the Rheumatic Diseases this month, addresses long-standing fears of a link between lupus medication and cancer.
Systemic lupus erythematosus (SLE), commonly known as lupus, is an autoimmune disease in which the body's immune ...
LAST 30 PRESS RELEASES:
Reality check: making indoor smartphone-based augmented reality work
Overthinking what you said? It’s your ‘lizard brain’ talking to newer, advanced parts of your brain
Black men — including transit workers — are targets for aggression on public transportation, study shows
Troubling spike in severe pregnancy-related complications for all ages in Illinois
Alcohol use identified by UTHealth Houston researchers as most common predictor of escalated cannabis vaping among youths in Texas
Need a landing pad for helicopter parenting? Frame tasks as learning
New MUSC Hollings Cancer Center research shows how Golgi stress affects T-cells' tumor-fighting ability
#16to365: New resources for year-round activism to end gender-based violence and strengthen bodily autonomy for all
Earliest fish-trapping facility in Central America discovered in Maya lowlands
São Paulo to host School on Disordered Systems
New insights into sleep uncover key mechanisms related to cognitive function
USC announces strategic collaboration with Autobahn Labs to accelerate drug discovery
Detroit health professionals urge the community to act and address the dangers of antimicrobial resistance
3D-printing advance mitigates three defects simultaneously for failure-free metal parts
Ancient hot water on Mars points to habitable past: Curtin study
In Patagonia, more snow could protect glaciers from melt — but only if we curb greenhouse gas emissions soon
Simplicity is key to understanding and achieving goals
Caste differentiation in ants
Nutrition that aligns with guidelines during pregnancy may be associated with better infant growth outcomes, NIH study finds
New technology points to unexpected uses for snoRNA
Racial and ethnic variation in survival in early-onset colorectal cancer
Disparities by race and urbanicity in online health care facility reviews
Exploring factors affecting workers' acquisition of exercise habits using machine learning approaches
Nano-patterned copper oxide sensor for ultra-low hydrogen detection
Maintaining bridge safer; Digital sensing-based monitoring system
A novel approach for the composition design of high-entropy fluorite oxides with low thermal conductivity
A groundbreaking new approach to treating chronic abdominal pain
ECOG-ACRIN appoints seven researchers to scientific committee leadership positions
New model of neuronal circuit provides insight on eye movement
Cooking up a breakthrough: Penn engineers refine lipid nanoparticles for better mRNA therapies
[Press-News.org] Grammar undercuts security of long computer passwordsCarnegie Mellon researchers devise grammar-aware password cracker