{"id":{"repo_id":"uoit","oai_identifier":"oai:ontariotechu.scholaris.ca:10155/1593"},"canonical_url":"https://search.dev.ndltd.org/etd/uoit/oai:ontariotechu.scholaris.ca:10155/1593","repository":{"repo_id":"uoit","name":"Ontario Institute of Technology","base_url":"https://ontariotechu.scholaris.ca/server/oai/request"},"display":{"title":"Raising the bar for password crackers: improving the quality of honeywords with deep neural networks","abstract":"Honeywords are fictitious passwords inserted into databases in order to identify password breaches. Producing honeywords that are difficult to distinguish from actual passwords automatically is a time-consuming and sophisticated task, and the majority of existing research assumes that attackers have no knowledge about users, which is a flawed assumption. In this thesis, we introduce two honeyword generation techniques (HGT): Honey-GAN and Chunk-GPT3, which can generate honeywords resistant to trawling attacks and targeted attacks, respectively. In addition, we propose a trawling attack, termed as Normalized Top-SW, to imitate trawling attackers and further assess the resilience of HGTs to the attack. Furthermore, we propose two text similarity-based metrics to evaluate the indistinguishability of honeywords. We analyze our HGTs compared with the other two state-of-the-art HGTs quantitatively and qualitatively and demonstrate that our HGTs can produce honeywords that are substantially more difficult for attackers to distinguish, hence increasing the bar for attackers and accelerating the detection of password breaches.","abstract_html":"Honeywords are fictitious passwords inserted into databases in order to identify password breaches. Producing honeywords that are difficult to distinguish from actual passwords automatically is a time-consuming and sophisticated task, and the majority of existing research assumes that attackers have no knowledge about users, which is a flawed assumption. In this thesis, we introduce two honeyword generation techniques (HGT): Honey-GAN and Chunk-GPT3, which can generate honeywords resistant to trawling attacks and targeted attacks, respectively. In addition, we propose a trawling attack, termed as Normalized Top-SW, to imitate trawling attackers and further assess the resilience of HGTs to the attack. Furthermore, we propose two text similarity-based metrics to evaluate the indistinguishability of honeywords. We analyze our HGTs compared with the other two state-of-the-art HGTs quantitatively and qualitatively and demonstrate that our HGTs can produce honeywords that are substantially more difficult for attackers to distinguish, hence increasing the bar for attackers and accelerating the detection of password breaches.","abstract_has_math":false,"creators":["Yu, Fangyi"],"institution":"University of Ontario Institute of Technology","degree_name":"Master of Science (MSc)","degree_level":null,"degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":[],"advisors":["Vargas Martin, Miguel"],"committee_chairs":[],"committee_members":[],"year":2022,"date_issued":"2022-12-01","date_published":"2022-12-01","updated_at":"2026-07-24T05:35:18Z","subjects":["Generative adversarial networks","Honeywords","Authentication","Security and privacy","Natural language processing"],"languages":["en"],"rights":[],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/10155/1593","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Vargas Martin, Miguel"]},{"key":"dc:creator","label":"Author","values":["Yu, Fangyi"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2023-03-13T19:41:03Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2023-03-13T19:41:03Z"]},{"key":"dc:date.issued","label":"Date","values":["2022-12-01"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master of Science (MSc)"]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Ontario Institute of Technology"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Generative adversarial networks","Honeywords","Authentication","Security and privacy","Natural language processing"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language.iso","label":"Language (ISO)","values":["en"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/10155/1593"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Honeywords are fictitious passwords inserted into databases in order to identify password breaches. Producing honeywords that are difficult to distinguish from actual passwords automatically is a time-consuming and sophisticated task, and the majority of existing research assumes that attackers have no knowledge about users, which is a flawed assumption. In this thesis, we introduce two honeyword generation techniques (HGT): Honey-GAN and Chunk-GPT3, which can generate honeywords resistant to trawling attacks and targeted attacks, respectively. In addition, we propose a trawling attack, termed as Normalized Top-SW, to imitate trawling attackers and further assess the resilience of HGTs to the attack. Furthermore, we propose two text similarity-based metrics to evaluate the indistinguishability of honeywords. We analyze our HGTs compared with the other two state-of-the-art HGTs quantitatively and qualitatively and demonstrate that our HGTs can produce honeywords that are substantially more difficult for attackers to distinguish, hence increasing the bar for attackers and accelerating the detection of password breaches."]},{"key":"dc:title","label":"Title","values":["Raising the bar for password crackers: improving the quality of honeywords with deep neural networks"]}]}],"canonical_facts":{"dc:contributor.advisor":["Vargas Martin, Miguel"],"dc:creator":["Yu, Fangyi"],"dc:date.accessioned":["2023-03-13T19:41:03Z"],"dc:date.available":["2023-03-13T19:41:03Z"],"dc:date.issued":["2022-12-01"],"dc:description.abstract":["Honeywords are fictitious passwords inserted into databases in order to identify password breaches. Producing honeywords that are difficult to distinguish from actual passwords automatically is a time-consuming and sophisticated task, and the majority of existing research assumes that attackers have no knowledge about users, which is a flawed assumption. In this thesis, we introduce two honeyword generation techniques (HGT): Honey-GAN and Chunk-GPT3, which can generate honeywords resistant to trawling attacks and targeted attacks, respectively. In addition, we propose a trawling attack, termed as Normalized Top-SW, to imitate trawling attackers and further assess the resilience of HGTs to the attack. Furthermore, we propose two text similarity-based metrics to evaluate the indistinguishability of honeywords. We analyze our HGTs compared with the other two state-of-the-art HGTs quantitatively and qualitatively and demonstrate that our HGTs can produce honeywords that are substantially more difficult for attackers to distinguish, hence increasing the bar for attackers and accelerating the detection of password breaches."],"dc:identifier.uri":["https://hdl.handle.net/10155/1593"],"dc:language.iso":["en"],"dc:subject":["Generative adversarial networks","Honeywords","Authentication","Security and privacy","Natural language processing"],"dc:title":["Raising the bar for password crackers: improving the quality of honeywords with deep neural networks"],"dc:type":["Thesis"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_name":["Master of Science (MSc)"],"thesis:institution_name":["University of Ontario Institute of Technology"]},"updated_at":"2026-07-24T05:35:18Z"}