PCFG Password Guessing Method Based on hashcat and GPU Parallel Computing
By combining hashcat with GPU parallel computing technology, the CPU uses the CPU to preprocess PCFG model data and generate parallel passwords on the GPU side, the problem of slow generation of PCFG password guessing methods and lack of integrated solutions is solved, and efficient password cracking and fast password cracking are achieved.
Patent Information
- Application Number
- CN202210718908.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-23
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-06-23
AI Technical Summary
The existing PCFG password guessing methods are generated too slowly and lack an integrated solution with the practical tool hashcat, which leads to excessive time consumption when ciphertext password cracking.
Combining hashcat and GPU parallel computing technology, the PCFG model data is preprocessed by the CPU side and parallel password generation is generated using the designed index algorithm on the GPU side to realize parallel computing at the password level.
It significantly improves the speed of PCFG password cracking, reduces the time cost of password generation, and improves the cracking efficiency in real-life scenarios through integration with hashcat.
Smart Images

Figure CN115220913B_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of password security, and specifically is a PCFG password guessing method based on hashcat and GPU parallel computing. Background Art
[0002] Text passwords have been widely used in the field of identity authentication due to their low cost and ease of use. Password security researchers have been committed to finding efficient password guessing methods. Efficient password guessing methods can help password administrators better discover passwords that are easy to crack, and can also be used to obtain encrypted information in judicial evidence. As more and more plaintext password data has been leaked in recent years, data-driven password guessing based on mathematical probability models has become possible. Probabilistic context-free grammars (PCFG) and other probabilistic password guessing models have received increasing attention in the field of password security research. PCFG is trained on a plaintext password set, extracting passwords into structures (pre-terminals) composed of character fragments, using the product of the probability of the structure and the probability of its constituent strings (fragment elements) as the password probability, and generating guessed passwords in descending order of probability. Compared with practical password cracking tools such as hashcat that use rule-based attacks as their main attack method, PCFG, a guessing method based on mathematical probability models, has a higher guessing efficiency with the same number of guesses, that is, it can hit more passwords with fewer guesses. However, PCFG generates guessed passwords too slowly and is not practical in real attack scenarios. In addition, when cracking ciphertext passwords, it is necessary to use a pipeline mechanism in combination with practical tools to perform hashing and matching operations, which increases the time consumption. In general, the password generation speed of PCFG needs to be improved, and there is a lack of available integration solutions for PCFG and the practical tool hashcat. Summary of the invention
[0003] The purpose of the present invention is to provide a PCFG password guessing method with high cracking efficiency and strong scalability.
[0004] The PCFG password guessing method proposed by the present invention combines the practical password cracking tool hashcatt with GPU parallel computing technology; by preprocessing the model data obtained by PCFG model training on the CPU side and using the designed index algorithm in each thread on the GPU side to locate the password to be generated by the thread, PCFG can use GPU to achieve parallel password generation at the password level. The present invention not only utilizes the efficient password cracking efficiency of PCFG itself, but also utilizes GPU to accelerate the password generation speed, and by combining with the practical password cracking tool hashcat, the speed of cracking ciphertext passwords in real scenarios is further improved.
[0005] The PCFG password guessing method proposed by the present invention is specifically divided into three steps:
[0006] Step 1: Process PCFG model data on the CPU side
[0007] The processing of the model data is divided into two parts: constructing a fragment dictionary and reconstructing pre-terminals; by preprocessing the model data of the PCFG password guessing model on the CPU side, a fragment dictionary and a reconstructed pre-terminal structure are obtained; the fragment dictionary is passed to the GPU side for later use before the password cracking starts; when performing password cracking, a certain number of pre-terminal structures are generated and transmitted to the GPU side each time based on the GPU memory limit for the subsequent password guessing process. Among them:
[0008] (1) The construction of the fragment dictionary means storing all the fragment strings obtained by PCFG training in sequence as a dictionary (fragment dictionary), and after creation, it is passed to the GPU side for later use. Specifically, for all fragment elements (strings), they are sorted in the order of type, length, and probability, that is, first sorted by type, for fragment elements of the same type, sorted by length, and for all fragment elements of the same type and the same length, sorted by probability. For example, when sorting by type, the letter type is ranked first, and among the fragment elements of the letter type and length 1, the element "a" has the highest probability, so the fragment element "a" will be ranked first in the fragment dictionary;
[0009] Thus, the elements of different lengths of each type of fragment can be regarded as a group. For example, in the above example, all elements of the character type and length 1 are a group, and the first element of this group is "a". In order to obtain the positions of each group of elements, another one-dimensional array with a length of K*N is set to store the starting positions of all element groups in the fragment dictionary (i.e., the relative offset of "a" in the above example), where K is the number of fragment types and N is the maximum length of fragment elements. Through this one-dimensional array, the relative offset of an element in the entire fragment dictionary can be obtained through the number of the element in the group, so as to calculate the address of the element.
[0010] (2) The reconstruction of the pre-terminals is divided into three parts: probability redistribution of fragment elements, modification of the basic structure of the pre-terminals, and fine-tuning of the pre-terminal structure length, where the probability redistribution of fragment elements occurs before generating the pre-terminals.
[0011] (1)Before generating the pre-terminal, reallocate the probabilities of fragment elements of the same type and length to adjust the number of elements in each fragment of the pre-terminal, and then adjust the number of passwords that a pre-terminal will generate. By this method, when generating passwords in parallel on the GPU later, the threads in the same warp process the same pre-terminal, thereby reducing the waiting latency between threads. Specifically, for the elements of the same type and length in the fragment dictionary, reallocate the probabilities in groups of 8, so that each fragment in the generated pre-terminal contains 8 elements. For a pre-terminal containing 2 or more fragments, the number of generated passwords must be an integer multiple of 32 (the number of threads in a warp), and no other operations are required; but for a pre-terminal containing only one fragment, it is necessary to repeat this pre-terminal 4 times so that the number of generated passwords reaches 32.
[0012] (2)Modify the basic structure of the pre-terminal. In the original pre-terminal structure, each pre-terminal needs to store the type, length, probability, and specific elements (string array) contained in each fragment. When modifying the pre-terminal, first add four values to each pre-terminal structure, namely offset, segment size, previous guesses, and current guesses. Secondly, for each fragment that makes up the pre-terminal, retain the two basic pieces of information, type and fragment length, remove the probability information and the specific element string stored in the original structure, and add two new values, namely the start index of item and item size. This not only reduces the redundant storage of the original structure but also prepares for the subsequent index calculation.
[0013] Among them, the specific meanings of the newly added types of values are as follows:
[0014] The offset records the thread number corresponding to the last guessed password to be generated by the previous pre-terminal (the thread number starts from 1, and the initial 0 corresponds to the maximum thread number), which can be used to calculate the thread number corresponding to the first guessed password to be generated by the current pre-terminal.
[0015] The segment size records the number of password fragments that make up the current pre-terminal, which can be used to judge the storage boundary of the specific fragment data that makes up this pre-terminal.
[0016] The previous guesses record the total number of guessed passwords generated by all pre-terminals before the current pre-terminal, which can be used to calculate the position of a certain guessed password generated by the current pre-terminal among all the guessed passwords generated by the guessing method.
[0017] The current guess count records the total number of guessed passwords that the current pre-terminal can generate, and can be used to determine whether all the generation tasks of the guessed passwords have been assigned for the current pre-terminal.
[0018] The element start number records the offset of the first element in the current segment among the elements of the same type and the same length in the segment dictionary. Since all the elements of the segments in a pre-terminal are of the same type, the same length and the same probability, all these elements are stored continuously in the segment dictionary. Therefore, only the offset of the first element needs to be stored.
[0019] The element count records the number of strings contained in the elements of the current segment, and can be used together with the length to determine the address boundary of the elements in the segment dictionary.
[0020] (3)Fine-tune the structure size of a single pre-terminal. Considering that the memory access of the GPU is always executed in units of cache lines, and the cache line size is usually 128 bytes, the total length of a pre-terminal can be made an integer multiple of the GPU cache line size on the basis of reducing the pre-terminal structure length, so as to reduce the number of memory accesses when obtaining the pre-terminal. Specifically, in a pre-terminal structure, 8 bytes, 1 byte, 8 bytes, and 7 bytes are used to store the offset, the segment count, the previous guess count, and the current guess count respectively; for each segment contained in the pre-terminal, 1 byte, 1 byte, 1 byte, and 5 bytes are used to store the type, the length, the element start number, and the element count respectively, and it is limited that a pre-terminal contains at most 29 segments. Thus, the size of a pre-terminal is 256 bytes, avoiding the problem of inefficient reading caused by memory misalignment.
[0021] The pre-terminal structure created according to the above steps is passed to the GPU side for subsequent password generation. Since the GPU memory is limited and all pre-terminals cannot be processed at one time, the pre-terminal structures need to be generated and processed in batches, where the number of each batch is limited to the integer quotient of 90% of the remaining available video memory divided by the space size occupied by a single pre-terminal (i.e., 256 bytes). In addition, the generation and processing of the pre-terminals are designed as two threads running in parallel to further improve the speed.
[0022] Step 2: Generate and match guessed passwords in parallel on the GPU side
[0023] According to the information in the pre-terminal structure passed to the GPU each time, using the designed indexing algorithm, the password to be generated and the positions of its corresponding segment elements in the segment dictionary are determined in each GPU thread, so as to generate guessed passwords. For each guessed password, the hash processing and ciphertext matching interfaces provided by hashcat are called. If the matching is successful, the current guessed index values (pt_id and guess_id) are reserved for the subsequent reconstruction of the cleartext password on the CPU.
[0024] Among them, the designed indexing algorithm is used to generate guessed passwords, which is divided into two parts:
[0025] (1) Use pt_id-guess_id to represent the guess_id-th guessed password generated by the pt_id-th pre-terminal. Thus, in the GPU, for each thread numbered thread_id, the following formula can be used to calculate the guess_id of the password that the thread needs to generate when processing the pre-terminal numbered pt_id by traversing pt_id:
[0026]
[0027] Among them, thread_size represents the total number of threads used, and offset and current_guess are the offset and current guess stored in each pre-terminal structure respectively. The specific process is to traverse each pt_id starting from 1. For each pt_id, obtain the offset and current_guess stored in it, and then traverse 𝛼 starting from 0 to calculate the guess_id of the password that needs to be generated in the current pt_id until the obtained guess_id > current_guess, and then start processing the next pt_id.
[0028] (2) A pre-terminal generates a password by sequentially selecting elements from each segment. From left to right, first traverse all the elements of the i-th segment, and for each element of segment i, traverse all the elements of the (i + 1)-th segment. Therefore, after knowing the pt_id and guess_id corresponding to the password, the element numbers seg_id of each segment that make up the guessed password can be inversely deduced based on guess_id by converting a one-dimensional array into a multi-dimensional array. Also, because in the pre-terminal structure, the offset (start index of item) of the starting element of each segment in the group (same type, same length) in the segment dictionary is stored, adding this value to seg_id can calculate the offset of the element in the group in the segment dictionary. Then, use the starting address of each group of elements in the segment dictionary stored in the one-dimensional array of K*N, and add the offset value to calculate the address of the element, so as to obtain the specific string in the segment dictionary. Thus, concatenate the element strings of each segment to finally obtain the guessed password.
[0029] Step 3. Reconstruct and output the hit password on the CPU side
[0030] For the successfully matched password, the index information (pt_id and guess_id) corresponding to the guessed password is sent back to the CPU side. On the CPU side, the plaintext of the hit password is reconstructed according to the indexing algorithm described in Step 2, thus successfully recovering the plaintext password, and finally outputting the cracking information to the specified location.
[0031] The guessing method of the present invention is compatible with the running process of hashcat and can be directly implemented as an attack mode in hashcat. While utilizing the high guessing efficiency of PCFG, the present invention reduces the time cost of password generation by using GPU parallel computing; by combining the PCFG password generation process with the hashcat running process, the transmission delay of the combined use of the probability guessing model and the practical cracking tool is reduced.
[0032] Technical effects
[0033] The guessing method proposed by the present invention can effectively improve the password cracking speed of PCFG. Through cross-site password guessing experiments on the password sets leaked in the real world (CSDN, 178, Youku, Rockyou, Neopets, Cit0Day), the improvement effect of the present invention is verified. Within the same time, the cracking rate that the present invention can achieve is, on average, 14.85% higher than that of the currently best PCFG cracking method (the combination of C version PCFG and hashcat through a pipeline), and the highest can reach 27.42%.
[0034] The guessing method proposed by the present invention is easy to expand. For other versions of PCFG, as long as they still classify segments by length, only the syntax dictionary and pre-terminal structure need to be adjusted according to the PCFG model syntax used during implementation. Additionally, since the guessing method proposed by the present invention does not affect the running logic of hashcat itself, there is no need for excessive modification in the case of hashcat version updates.
[0035] The present invention is easy to operate. The present invention implements the PCFG password cracking method as an attack mode of hashcat. When using this attack mode, only the directory where the model data of PCFG needs to be provided to hashcat additionally in the form of parameters in the command line when running hashcat, and other options are no different from using the original hashcat.
[0036] The guessing method proposed by the present invention has requirements for the PCFG segment division method. If there is no length information in the segment division, such as classifying segments by syntax, the alignment and design scheme of the dictionary need to be reconsidered when implementing it into hashcat. Brief description of the drawings
[0037] Figure 1 It is the flowchart of the running process of the guessing method proposed by the present invention. Detailed implementation manners
[0038] The embodiments of the present invention will be described in detail below, with specific implementation methods and operation processes given, but the protection scope of the present invention is not limited to the following embodiments.
[0039] Before using the present invention, it is necessary to first generate a training model using the corresponding version of PCFG.
[0040] The present invention implements the PCFG password cracking method as an attack mode of hashcat. When using this attack mode, only the directory where the model trained by PCFG is located needs to be additionally provided to hashcat in the form of parameters in the command line when running hashcat, and other options are no different from using the original hashcat.
[0041] An example of the command line for running the present invention is as follows:
[0042] . / hashcat -a 11 -m 99999 -o result.txt --pcfg-base-directory= / pcfg_ model / target.txt
[0043] Among them: -a specifies the attack mode, and the PCFG attack model in the present invention is set to 11 which is not used by hashcat; -m specifies the hash algorithm used by the target file. Here, 99999 represents plaintext, that is, the target file is not encrypted using a hash algorithm; -o specifies the path of the output file for storing the cracking result; --pcfg-base-directory specifies the path where the PCFG training data used is located; the last parameter (target.txt) specifies the path of the target file.
Claims
1. A PCFG password guessing method based on hashcat and GPU parallel computing, characterized in that, by preprocessing the model data obtained from PCFG model training on the CPU side and using the designed indexing algorithm in each GPU thread to locate the passwords that the thread needs to generate, enabling PCFG to achieve parallel password generation at the password level using the GPU; and by combining with the practical password cracking tool hashcat, the speed of cracking ciphertext passwords in real scenarios is improved; the specific steps are as follows: Step 1. Process PCFG model data on the CPU side The processing of model data is divided into two parts: constructing a fragment dictionary and reconstructing pre-terminals; by preprocessing the model data of the PCFG password guessing model on the CPU side, a fragment dictionary and a reconstructed pre-terminal structure are obtained; the fragment dictionary is passed to the GPU side for later use before password cracking starts; when performing password cracking, a certain number of pre-terminal structures are generated and transmitted into the GPU side based on the GPU memory limit each time for the subsequent password guessing process; Step 2. Parallelly generate and match guessed passwords on the GPU side According to the information in the pre-terminal structure passed into the GPU each time, use the indexing algorithm to determine the passwords to be generated and the positions of their corresponding fragment elements in the fragment dictionary in each GPU thread, thereby generating guessed passwords; after processing the generated guessed passwords according to the corresponding hash algorithm, match them in the ciphertext password file, and for the guessed passwords that match successfully, record their index information and send it back to the CPU side; Step 3. Reconstruct and output the hit passwords on the CPU side For the passwords that match successfully, their corresponding index information is sent back to the CPU side, and the plaintext of the hit passwords is reconstructed using the indexing algorithm on the CPU side to complete password recovery, and finally the cracking information is output to the specified location; In Step 1, the construction of the fragment dictionary means storing all the fragment strings obtained from PCFG training in a dictionary in order; the specific process is as follows: (1) For all fragment elements, that is, strings, sort them in order of type, length, and probability, that is, first sort by type, and for fragment elements of the same type, sort by length, and for all fragment elements of the same type and the same length, sort by probability; (2) Consider the elements of different lengths of each type of fragment as a group. To obtain the positions of each group of elements, another one-dimensional array with a length of K*N is set to store the starting positions of all element groups in the fragment dictionary, where K is the number of fragment types and N is the maximum length of fragment elements; through this one-dimensional array, according to the number of an element in the group, the relative offset of the element in the entire fragment dictionary can be obtained, thereby calculating the address of the element; In Step 1, the specific process of reconstructing pre-terminals is divided into three parts: fragment element probability redistribution, modifying the basic structure of pre-terminals, and fine-tuning the length of pre-terminal structures; (1) Fragment element probability redistribution is to redistribute the probabilities of fragment elements of the same type and length before generating pre-terminals, so as to adjust the number of elements in each fragment of the pre-terminal, and then adjust the number of passwords that a pre-terminal will generate, so that when generating passwords in parallel on the GPU, the threads in the same warp process the same pre-terminal, thereby reducing the waiting latency between threads; specifically, for elements of the same type and length in the fragment dictionary, redistribute the probabilities in groups of 8, so that each fragment in the generated pre-terminal contains 8 elements; for pre-terminals containing 2 or more fragments, the number of generated passwords is an integer multiple of 32, and no other operations are required; for pre-terminals containing only one fragment, repeat the pre-terminal 4 times so that the number of generated passwords reaches 32; (2) Modify the basic structure of the pre-terminal; in the original pre-terminal structure, each pre-terminal stores the type, length, probability corresponding to each fragment and the specific elements contained therein, that is, a string array; to modify the basic structure of the pre-terminal, first, add four values in each pre-terminal structure, namely offset, number of fragments, previous guess number, and current guess number; second, for each fragment constituting the pre-terminal, retain the two basic information items of type and fragment length, remove the probability information and specific element strings stored in the original structure, and add two values, namely element start number and number of elements; This reduces the redundant storage of the original structure and prepares for subsequent index calculation; (3) Fine-tuning the length of the pre-terminal structure is to fine-tune the size of a single pre-terminal structure; considering that the memory access of the GPU is always executed in units of cache lines, and the cache line size is 128 bytes, on the basis of reducing the length of the pre-terminal structure, make the total length of a pre-terminal an integer multiple of the GPU cache line size, so as to reduce the number of memory accesses when obtaining the pre-terminal; specifically, in a pre-terminal structure, use 8 bytes, 1 byte, 8 bytes, and 7 bytes to store the offset, number of fragments, previous guess number, and current guess number respectively; for each segment contained in the pre-terminal, use 1 byte, 1 byte, 1 byte, and 5 bytes to store the type, length, element start number, and number of elements respectively, and limit a pre-terminal to contain at most 29 fragments; In step two, the specific process of generating guessed passwords using the index algorithm is as follows: (1) Use pt_id-guess_id to represent the guess_id-th guessed password generated by the pt_id-th pre-terminal; thus, in the GPU, for each thread numbered thread_id, use the following formula to calculate the guess_id of the password that the thread needs to generate when processing the pre-terminal numbered pt_id by traversing pt_id: guess_id = (thread_id - offset + thread_size) % thread_size + α × thread_size, 0 < guess_id ≤ current_guess Among them, thread_size represents the total number of threads used, and offset and current_guess are the offset and current guess number stored in each pre-terminal structure respectively; the specific process is as follows: starting from 1, traverse each pt_id, for each pt_id, obtain the stored offset and current_guess, and then start traversing α from 0 to calculate the guess_id of the password to be generated in the current pt_id until the obtained guess_id > current_guess, then start processing the next pt_id; (2) A pre-terminal generates a password by sequentially selecting elements in each segment; from left to right, first traverse all elements of the i-th segment, and for each element of segment i, traverse all elements of the (i + 1)-th segment; therefore, after knowing the pt_id and guess_id corresponding to the password, using the method of converting a one-dimensional array into a multi-dimensional array, based on the guess_id, inversely deduce the element number seg_id of each segment that makes up the guessed password; since in the pre-terminal structure, each segment stores the initial offset of the starting element in the group where it is located in the segment dictionary, adding the initial offset value and seg_id can calculate the actual offset of the element in the group where it is located in the segment dictionary; then use the starting address of each group of elements in the segment dictionary stored in the one-dimensional array of K * N, plus the actual offset value to calculate the address of the element, so as to obtain the specific string in the segment dictionary; concatenate the element strings of each segment to finally obtain the guessed password.
2. The PCFG password guessing method according to claim 1, characterized in that, in step one: the offset records the thread number corresponding to the last guessed password to be generated by the previous pre-terminal, and can be used to calculate the thread number corresponding to the first guessed password to be generated by the current pre-terminal; the number of segments records the number of password segments that make up the current pre-terminal, and can be used to judge the storage boundary of the specific segment data that makes up the pre-terminal; the previous guess number records the total number of guessed passwords generated by all pre-terminals before the current pre-terminal, and can be used to calculate the position of a certain guessed password generated by the current pre-terminal among all guessed passwords generated by the guessing method; the current guess number records the total number of guessed passwords that the current pre-terminal can generate, and can be used to judge whether the current pre-terminal has completed all tasks of generating guessed passwords; the starting element number records the offset of the first element in the current segment among elements of the same type and the same length in the segment dictionary; the number of elements records the number of strings included in the elements in the current segment, and can be used together with the length to judge the address boundary of the elements in the segment dictionary.