论文标题

PassLab:蓝色团队的密码安全工具

Passlab: A Password Security Tool for the Blue Team

论文作者

Johnson, Saul

论文摘要

如果我们希望将某些受密码保护的系统作为攻击者(即红色团队的成员)妥协,那么我们将有大量流行且积极维护的工具可供选择,以帮助我们实现自己的目标。密码哈希破解硬件和软件,在线猜测工具,利用框架以及可帮助我们在目标系统上进行侦察的大量工具。相比之下,如果我们希望为受密码保护的系统辩护,以防止这种攻击(即作为蓝色团队的成员),我们有相对较少的工具可供选择。在这项研究摘要中,我们介绍了迄今为止的工作PassLab,这是一种密码安全工具,旨在帮助系统管理员利用正式方法,以便使用干净和直观的用户界面来做出明智和基于证据的安全性决策。

If we wish to compromise some password-protected system as an attacker (i.e. a member of the red team), we have a large number of popular and actively-maintained tools to choose from in helping us to realise our goal. Password hash cracking hardware and software, online guessing tools, exploit frameworks, and a wealth of tools for helping us to perform reconnaissance on the target system are widely available. By comparison, if we wish to defend a password-protected system against such an attack (i.e. as a member of the blue team), we have comparatively few tools to choose from. In this research abstract, we present our work to date on Passlab, a password security tool designed to help system administrators take advantage of formal methods in order to make sensible and evidence-based security decisions using a clean and intuitive user interface.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源