Please use this identifier to cite or link to this item: https://dspace.ncfu.ru/handle/123456789/29405
Full metadata record
DC FieldValueLanguage
dc.contributor.authorBabenko, M. G.-
dc.contributor.authorБабенко, М. Г.-
dc.contributor.authorLapina, M. A.-
dc.contributor.authorЛапина, М. А.-
dc.date.accessioned2024-12-13T12:05:51Z-
dc.date.available2024-12-13T12:05:51Z-
dc.date.issued2024-
dc.identifier.citationRusanov M., Babenko M., Lapina M., Sajid M. Identification of Exploited Unreliable Account Passwords in the Information Infrastructure Using Machine Learning Methods // Big Data and Cognitive Computing. - 2024. - 8 (11). - art. no. 159. - DOI: 10.3390/bdcc8110159ru
dc.identifier.urihttps://dspace.ncfu.ru/handle/123456789/29405-
dc.description.abstractAccounts are an integral part of most modern information systems and provide their owners with the ability to authenticate within the system. This paper presents an analysis of existing methods for detecting simple account passwords in automated systems. Their advantages and disadvantages are listed. A method was developed to detect simple exploitable passwords that administrators can use to supplement other existing methods to increase the overall security of automated systems against threats from accounts potentially compromised by attackers. The method was based on the analysis of commands executed in automated or manual modes with the indication of credentials in plain text. Minimum password strength requirements are provided based on the security level. A special case was considered in which all passwords analyzed in this way were found explicitly in the system logs. We developed a unified definition of the classification of passwords into simple and strong, and also developed machine learning technology for their classification. The method offers a flexible adaptation to a specific system, taking into account the level of significance of the information being processed and the password policy adopted, expressed in the possibility of retraining the machine learning model. The experimental method using machine learning algorithms, namely the ensemble of decision trees, for classifying passwords into strong and potentially compromised by attackers based on flexible password strength criteria, showed high results. The performance of the method is also compared against other machine learning algorithms, specifically XGBoost, Random Forest, and Naive Bayes. The presented approach also solves the problem of detecting events related to the use and storage of credentials in plain text. We used the dataset of approximately 770,000 passwords, allowing the machine learning model to accurately classify 98% of the passwords by their significance levels.ru
dc.language.isoenru
dc.publisherMultidisciplinary Digital Publishing Institute (MDPI)ru
dc.relation.ispartofseriesBig Data and Cognitive Computing-
dc.subjectInformation securityru
dc.subjectMachine Learningru
dc.subjectPasswordru
dc.subjectPassword policyru
dc.titleIdentification of Exploited Unreliable Account Passwords in the Information Infrastructure Using Machine Learning Methodsru
dc.typeСтатьяru
vkr.instФакультет математики и компьютерных наук имени профессора Н.И. Червяковаru
Appears in Collections:Статьи, проиндексированные в SCOPUS, WOS

Files in This Item:
File Description SizeFormat 
WoS 2032.pdf
  Restricted Access
112.26 kBAdobe PDFView/Open
scopusresults 3371.pdf
  Restricted Access
128.22 kBAdobe PDFView/Open


Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.