Research Article

Understanding Offline Password-Cracking Methods: A Large-Scale Empirical Study

Table 2

Empirical evaluation of cracking under extensive-knowledge.

Training datasetsBest64 (%)OMEN (%)OMEN-5 (%)PCFG (%)PCFG-4 (%)FLA (%)GAN (%)

16352.9252.0946.1557.9160.4456.7540.34
Duduniu60.8843.7444.1251.5552.5449.1234.06
17872.7763.9664.2867.3669.3977.4949.51
CSDN46.7541.0938.8147.0247.2556.8031.90
Sinaweibo53.7556.9755.9449.6458.3867.1043.61
Duowan40.9649.8846.3541.3349.0458.5530.71
Rockyou67.6053.3655.4669.3469.9977.9132.34
000Webhost43.3716.5617.8130.2635.3516.397.94
Xato61.3447.9047.7360.3362.3568.6332.92
Gmail52.3245.7450.0554.7257.2763.2228.83
Yahoo38.6642.4643.4648.2749.6150.2726.12
Phpbb40.9354.4944.9243.2153.1151.4237.80

1Each value in this table represents the fraction of passwords been cracked in a dataset (e.g., 52.93% means that 52.92 percent passwords of 163 targeting dataset have been cracked by 163-trained Best64).