HoneyHash: Honeyword Generation Based on Transformed Hashes

Canyang Shi,Huiping Sun
DOI: https://doi.org/10.1007/978-3-030-70852-8_10
2021-01-01
Abstract:Since systems using honeywords store a set of decoy passwords together with real passwords of users to confuse adversaries, they are strongly dependent on the algorithm for generating honeywords. However, all of the existing honeyword generating algorithms are based on raw passwords of users and they either need lots of storage space or show weaknesses in flatness or usability. This paper proposes HoneyHash, a new direction of generating honeywords - generating by transforming password hashes. Analyses show that our algorithm attains expected levels of flatness, security, performance and usability.
What problem does this paper attempt to address?