Research Article

Understanding Offline Password-Cracking Methods: A Large-Scale Empirical Study

Table 3

Empirical evaluation of cracking under limited-knowledge.

Targeting datasetsBest64 (%)OMEN (%)PCFG (%)PCFG-4 (%)FLA (%)GAN (%)
Trained on Rockyou

16334.6835.8630.0136.2747.2918.15
17839.8237.7638.3342.0853.0619.36
Duowan25.2927.8021.6227.2340.929.87
CSDN29.9230.1728.7031.9836.9713.28
000Webhost21.5314.0529.2124.2328.535.44
Gmail54.0941.3956.7655.8864.6523.11
Phpbb58.4644.1659.4858.9568.2427.34
Yahoo54.3839.5259.2355.6663.7521.63

Trained on Xato
16331.0133.4323.8634.0345.4822.48
17836.7939.6534.5341.8351.2123.95
Duowan21.2226.1216.7325.5238.4212.28
CSDN28.1029.5026.2130.9935.4015.11
000Webhost19.0713.9727.0723.4626.445.18
Gmail49.3639.3851.1652.4560.2123.53
Phpbb55.8444.5355.7857.5465.3929.17
Rockyou55.6945.3857.3660.0667.6130.39

Trained on Yahoo
16313.5428.2713.8920.6229.0613.84
17819.7833.7525.0228.9932.0717.94
Duowan8.3420.0810.3014.6418.996.52
CSDN17.2527.7218.7423.7724.636.61
000Webhost10.4014.7920.6018.8515.778.32
Gmail31.5341.4937.6642.6144.8625.80
Phpbb37.5944.7341.0746.2349.3030.91
Rockyou37.0148.6043.7350.7452.8433.37

Trained on Duduniu
000Webhost16.698.5620.3217.5016.344.85
Gmail44.7119.9043.3440.9639.9815.90
Phpbb51.0919.9047.7545.4442.3417.85
Rockyou52.4721.6250.8748.6648.7519.32
16349.3148.8843.2046.8654.3241.89
17857.3057.3754.1856.7756.6348.37
Duowan43.6148.0239.3643.9352.2936.52
CSDN40.3742.8638.7139.3446.4930.86

Trained on CSDN
000Webhost10.325.2414.2912.3412.273.47
Gmail27.1010.9127.3725.9329.849.53
Phpbb32.369.4830.5228.9232.238.97
Rockyou30.758.7630.1427.5131.259.43
16338.7830.6437.0137.1048.8932.79
17846.4637.9447.3445.5154.6738.25
Duowan33.2929.0134.4534.1546.5827.23
Sinaweibo43.4630.8140.7440.2850.5433.33

Trained on Sinaweibo
000Webhost14.4110.1822.5520.1718.064.48
Gmail41.0231.7542.9945.5448.3517.36
Phpbb48.0035.3647.4749.8253.6319.62
Rockyou48.6838.0250.4954.2357.2621.48
16339.7651.8635.9145.9755.9040.55
17845.8158.4245.8953.9662.5244.28
Duowan32.0948.3231.2740.3852.1234.85
CSDN35.0942.5535.6839.4646.4929.01

1Each value in this table represents the fraction of passwords been cracked in a dataset (e.g., 34.68% indicates that 34.68 percent passwords of 163 targeting dataset have been cracked by Rockyou-trained Best64).