A website weak password detection method, system, storage medium and intelligent terminal
By acquiring user information and website importance, dynamically adjusting the dictionary level, and combining it with the user's level of security awareness to conduct targeted weak password detection, the problem of low efficiency of traditional tools has been solved, achieving efficient and accurate weak password identification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHANXI SAIDUN NETWORK SECURITY EVALUATION TECH CO LTD
- Filing Date
- 2023-02-03
- Publication Date
- 2026-04-21
AI Technical Summary
Traditional weak password scanning tools are inefficient because they simulate logins using basic passwords during the brute-force process, and fixed dictionary tables cannot effectively identify users' personalized weak password habits.
By acquiring user information and website importance, the dictionary level is dynamically adjusted. Combined with the user's level of security awareness and the importance of the website, targeted weak password detection is carried out to reduce brute-force scanning.
It improves the efficiency and accuracy of weak password detection, reduces system computational load, and dynamically adjusts the dictionary level to adapt to users' personalized password setting habits.
Smart Images

Figure CN116127440B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of electronic information security technology, and in particular to a method, system, storage medium and smart terminal for detecting weak passwords on websites. Background Technology
[0002] With the rapid development of enterprise informatization, the importance of information system passwords is self-evident. A password is like a key to your house; if someone else has a key to your home, your security, your belongings, and your privacy are exposed. Because weak passwords are easily guessed or cracked, using a weak password is like leaving your house key under the doormat – extremely dangerous.
[0003] Traditional weak password scanning tools typically employ brute-force login attempts to crack passwords. They utilize weak password dictionaries to perform brute-force detection: first, they generate a mapping of usernames and passwords based on the weak password dictionary table; then, they simulate logins. If the login fails, they continue to detect the next mapping and simulate logins until successful or they brute-force all weak passwords to complete the scan.
[0004] Regarding the aforementioned technologies, the inventors believe that while the weak password dictionary is fixed, some individuals are inherently aware of weak passwords and typically do not use very basic passwords such as 888888. Therefore, if these passwords are still simulated during the brute-force attack process, it will result in unnecessary scanning, low efficiency, and room for improvement. Summary of the Invention
[0005] To address the issue of unnecessary scanning and low efficiency caused by simulating logins with very basic passwords during brute-force attacks, this application provides a website weak password detection method, system, storage medium, and smart terminal.
[0006] Firstly, this application provides a method for detecting weak passwords on websites, employing the following technical solution:
[0007] A method for detecting weak passwords on websites includes:
[0008] Obtain login website information, user information, and password information;
[0009] The importance of the login website information and user information is determined by matching and analyzing the importance information stored in the preset website database. This importance information is then defined as the website importance information.
[0010] Matching analysis is performed based on the protection awareness intensity information, user information, and website importance information stored in the preset evaluation database to determine the protection awareness intensity corresponding to the user information and website importance information, and the protection awareness intensity is defined as the possible protection awareness intensity information.
[0011] The dictionary level information and the possible protection awareness intensity information stored in the preset level database are matched and analyzed to determine the dictionary level corresponding to the possible protection awareness intensity information, and the dictionary level information is defined as the theoretical dictionary level information.
[0012] Match weak passwords and password information contained in dictionaries at the theoretical dictionary level and above;
[0013] If a match is found, output the weak password information.
[0014] If the match fails, output the normal password information.
[0015] By adopting the above technical solution, the likelihood of users using weak passwords can be determined by understanding users' security awareness and the importance of the website to users. This allows for targeted weak password detection at the corresponding level, eliminating the need for exhaustive searches, reducing the system's computational burden, and improving the efficiency of weak password detection.
[0016] Optionally, it also includes a method for classifying levels corresponding to dictionary-level information, which includes:
[0017] Obtain basic weak password dictionary information and basic dictionary-level information that are not associated with user information;
[0018] Based on user information, analyze the user's own data and user-related data;
[0019] Based on the preset weak password compilation rules, the user's own data information and the user's associated data information are compiled separately to obtain the user's own weak password information and the user's associated weak password information.
[0020] Both the user's own weak password information and the user's associated weak password information are added to the dictionary to form the user's own weak password dictionary information and the user's associated weak password dictionary information. The user's own level information and the user's associated level information are set, where the user's associated level information is higher than the level corresponding to the user's own level information.
[0021] Weak password groups are formed by arbitrarily selecting weak passwords from the basic weak password dictionary, the user's own weak password dictionary, and the dictionary corresponding to the user's associated weak password dictionary. The combination level information corresponding to the combined content of the weak password group information is added together to obtain the combination level information corresponding to the weak password group information.
[0022] By adopting the above technical solution, the dictionary level is determined based on the degree of relevance to the user, and then the upper limit of the dictionary level is determined based on different combinations, thereby dynamically providing the dictionary level, so that the dictionary for the user at each stage is timely and the accuracy of the dictionary level is improved.
[0023] Optionally, the level classification method corresponding to dictionary-level information further includes:
[0024] Select any level and define that level as the current level information;
[0025] Determine if the number of information types at the current level is greater than one;
[0026] If there are no more than one, the current level information will be output normally;
[0027] If there is more than one, then determine whether one of the current level information is a single-category level information, where single-category level information includes basic dictionary level information, user self-level information, and user associated level information;
[0028] If so, then increase the level corresponding to the single-category level information and continue to determine whether the number of types of the current level information is greater than one;
[0029] If not, remove the same single-category level information from the combined level information and filter out the single-category level information of the highest level, and define the single-category level information of the highest level as the highest single-category level information.
[0030] Compare and sort the maximum category level information corresponding to all combination level information to obtain the combination category order information;
[0031] The levels of the combined level information contained in the current level information are added sequentially according to the order of the combined category information, and the current level information is updated.
[0032] By adopting the above technical solution, and by determining the single-category level information within each combination and then sorting them according to priority, there are no two possibilities within the same level, making the dictionary level distinction clearer and more accurate, and improving the accuracy of dictionary level selection.
[0033] Optionally, methods for determining theoretical dictionary level information by matching and analyzing dictionary level information and potential awareness intensity information stored in the level database include:
[0034] Determine the highest level in the dictionary-level information and define that level as the highest-level information.
[0035] The number of mapping intervals is determined based on the highest level of information and the preset maximum level of protective awareness.
[0036] Weak passwords contained in dictionary-level information are classified according to preset classification rules to obtain weak password type information.
[0037] Calculate the number of weak password types in the same dictionary-level information;
[0038] Adjust the consciousness intensity range information corresponding to the number of mapping areas based on the number of weak password types;
[0039] Establish a mapping relationship between consciousness intensity range information and dictionary-level information, and form a level database;
[0040] Get the current weak password detection results;
[0041] When the current weak password detection result is a weak password, determine whether the consciousness strength range information corresponding to the weak password is accurate;
[0042] If so, continue using the level database;
[0043] If not, update the level database based on the current weak password detection results.
[0044] By adopting the above technical solution, the database is corrected in real time based on the results of each test, enabling the database to enter deep learning and continuously improve its adaptability to better match users' password setting habits.
[0045] Optionally, methods for matching weak passwords and password information contained in dictionaries at or above the theoretical dictionary level include:
[0046] The password information is parsed according to the classification rules to obtain the password type information;
[0047] Determine whether the password type information is consistent with the weak password type information at or above the level corresponding to the theoretical dictionary level information;
[0048] If they match, then proceed with the matching.
[0049] If there is a discrepancy, the weak password type information corresponding to that dictionary-level information will be temporarily deleted and not matched.
[0050] When the password type information and the weak password type information corresponding to all theoretical dictionary level information are inconsistent with each other, the normal password information is output directly.
[0051] By adopting the above technical solution, the amount of computation is reduced and the efficiency of weak password detection is improved by first determining the type and then excluding content corresponding to dictionary levels that are not of the same type.
[0052] Optionally, when the password type information and the weak password type information corresponding to all theoretical dictionary level information and above are inconsistent, the methods for directly outputting the normal password information include:
[0053] Based on the theoretical dictionary level information, determine the dictionary level information of the next lower level, and define the dictionary level information as the adjacent dictionary level information;
[0054] Weak passwords contained in adjacent dictionary-level information are classified according to classification rules to obtain adjacent weak password type information.
[0055] Determine whether the adjacent weak password type information and the type of password type information exist in the adjacent dictionary-level information;
[0056] If they exist, the weak passwords corresponding to the adjacent weak password types that are successfully matched will be matched with the password information.
[0057] Update the level database when a match is successful;
[0058] If it does not exist, output the normal password information directly.
[0059] By adopting the above technical solution, if the detection is inconsistent, it is possible to try to match the weak passwords with the lower-level dictionary weak passwords, thereby expanding the matching range, reducing the possibility of omissions due to slight errors in the level setting, and improving the accuracy of weak password identification.
[0060] Optionally, methods for updating the level database upon successful matching include:
[0061] Retrieve the number of adjacent weak password types and the range of adjacent awareness intensity corresponding to adjacent dictionary level information from the level database;
[0062] Retrieve the theoretical weak password types and quantity information and theoretical awareness intensity range information corresponding to the theoretical dictionary level information from the level database;
[0063] The adjacent consciousness intensity intervals are divided equally based on the number of adjacent weak password types to determine the equally divided adjacent consciousness intensity intervals.
[0064] The theoretical extension interval information is determined based on the information of adjacent consciousness intensity intervals and the information of equally divided adjacent consciousness intensity intervals;
[0065] The theoretical consciousness intensity range information is expanded and updated based on the theoretical extension range information.
[0066] When the password type information and the adjacent weak password type information are consistent, and the weak password corresponding to the adjacent dictionary level information always matches the password information, the theoretical extension interval information in the adjacent awareness strength interval information is deleted.
[0067] By adopting the above technical solution, the range of the theoretical consciousness intensity interval information is expanded, so that when a weak password that is clearly within the theoretical consciousness intensity interval information is consistent with the information of an adjacent consciousness intensity interval, the theoretical consciousness intensity interval information and the information of the adjacent consciousness intensity interval information are corrected in real time, thereby improving the adjustability of the consciousness intensity region for weak password detection.
[0068] Secondly, this application provides a website weak password detection system, which adopts the following technical solution:
[0069] A website weak password detection system includes:
[0070] The acquisition module is used to acquire login website information, user information, password information, basic weak password dictionary information, basic dictionary level information, and current weak password detection results.
[0071] The memory is used to store the program of the control method for any of the above-mentioned website weak password detection methods;
[0072] The processor and memory are control methods that can be loaded and executed by the processor to implement any of the above-mentioned website weak password detection methods.
[0073] By adopting the above technical solution, the likelihood of users using weak passwords can be determined by understanding users' security awareness and the importance of the website to users. This allows for targeted weak password detection at the corresponding level, eliminating the need for exhaustive searches, reducing the system's computational burden, and improving the efficiency of weak password detection.
[0074] Thirdly, this application provides a smart terminal, which adopts the following technical solution:
[0075] A smart terminal includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executed by any of the aforementioned website weak password detection methods.
[0076] By adopting the above technical solution, the likelihood of users using weak passwords can be determined by understanding users' security awareness and the importance of the website to users. This allows for targeted weak password detection at the corresponding level, eliminating the need for exhaustive searches, reducing the system's computational burden, and improving the efficiency of weak password detection.
[0077] Fourthly, this application provides a computer storage medium capable of storing corresponding programs, characterized by rapid reception and processing, and accurate analysis.
[0078] Computer-readable storage media adopt the following technical solutions:
[0079] A computer-readable storage medium storing a computer program that can be loaded by a processor and executed by any of the above-described website weak password detection methods.
[0080] By adopting the above technical solution, the likelihood of users using weak passwords can be determined by understanding users' security awareness and the importance of the website to users. This allows for targeted weak password detection at the corresponding level, eliminating the need for exhaustive searches, reducing the system's computational burden, and improving the efficiency of weak password detection.
[0081] In summary, this application includes at least the following beneficial technical effects:
[0082] 1. By understanding users' security awareness and the importance of the website to them, the likelihood of users using weak passwords can be determined, reducing the system's computational load and improving the efficiency of weak password detection;
[0083] 2. The dictionary level is determined based on the degree of relevance to the user, and the dictionary level is provided dynamically, so that the dictionary for the user at each stage is timely and the accuracy of the dictionary level is improved;
[0084] 3. By first determining the category and then excluding content corresponding to dictionary levels that are not of the same category, the amount of computation is reduced and the efficiency of weak password detection is improved. Attached Figure Description
[0085] Figure 1 This is a flowchart of a website weak password detection method in an embodiment of this application.
[0086] Figure 2 This is a flowchart of a method for classifying dictionary-level information in an embodiment of this application.
[0087] Figure 3 This is a flowchart of a further method for classifying the levels corresponding to the dictionary-level information in the embodiments of this application.
[0088] Figure 4 This is a flowchart illustrating a method for determining theoretical dictionary level information by matching and analyzing dictionary level information stored in a level database with potential protection awareness intensity information, as described in this application embodiment.
[0089] Figure 5 This is a flowchart illustrating a method for matching weak passwords and password information contained in dictionaries at or above the theoretical dictionary level, as described in this application.
[0090] Figure 6This is a flowchart of a method for directly outputting normal password information when the password type information and the weak password type information corresponding to all theoretical dictionary level information and above are inconsistent, as described in this application embodiment.
[0091] Figure 7 This is a flowchart of a method for updating the level database when a match is successful, as described in an embodiment of this application.
[0092] Figure 8 This is a system module diagram of a website weak password detection method in an embodiment of this application. Detailed Implementation
[0093] To make the purpose, technical solution, and advantages of this application clearer, the following description is provided in conjunction with the appendix. Figure 1-8 The present application will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the application.
[0094] This application discloses a method for detecting weak passwords on websites. (Refer to...) Figure 1 One method for detecting weak passwords on websites includes:
[0095] Step 100: Obtain login website information, user information, and password information.
[0096] The login website information refers to the website you are currently logging into. User information includes all relevant user information, such as identity, education level, and age. Password information refers to the password you set for logging into the website.
[0097] Step 101: Match and analyze the importance information stored in the preset website database with the login website information and user information to determine the importance of the login website information and user information, and define the importance information as the website importance information.
[0098] Website importance information refers to how important a website is to a user. The database stores a mapping relationship between importance information, website login information, and user information. This information is categorized and entered into the database by professionals in this field based on internet big data, the website's own importance, and other data. For example, a bank website's account password is extremely important to a user and could be set to 80%, while a voting website, which is a one-time event for the user, would be output as 10%. When the system receives user information and website login information, it automatically retrieves the corresponding importance from the database and outputs the website importance information accordingly.
[0099] Step 102: Perform a matching analysis based on the protection awareness intensity information, user information, and website importance information stored in the preset evaluation database to determine the protection awareness intensity corresponding to the user information and website importance information, and define the protection awareness intensity as the possible protection awareness intensity information.
[0100] The potential security awareness level information refers to the level of security awareness a user might have when setting a password on this website. The database stores a mapping relationship between security awareness level information, user information, and website importance information, obtained by professionals in this field based on extensive data surveys. For example, a university student might have a high level of security awareness when logging into a bank's website, a relatively lower level of security awareness when logging into a gaming website, and an even weaker level of security awareness when logging into a college website. Elementary school students or adults with low levels of education might have no security awareness at all. Therefore, all this data is summarized and stored in the database. When the system receives user information and website importance information, it automatically retrieves the corresponding security awareness level from the database and outputs it as the potential security awareness level information.
[0101] Step 103: Perform a matching analysis based on the dictionary level information and possible protection awareness intensity information stored in the preset level database to determine the dictionary level corresponding to the possible protection awareness intensity information, and define the dictionary level information as theoretical dictionary level information.
[0102] The theoretical dictionary-level information refers to the password level that would theoretically be set if a user possesses sufficient awareness of potential security measures and uses a weak password. The database stores a mapping relationship between dictionary-level information and potential security awareness information, established by experts in the field based on experience. When the system receives potential security awareness information, it automatically retrieves the corresponding dictionary level from the database and outputs the theoretical dictionary-level information.
[0103] Step 104: Match weak passwords and password information contained in dictionaries at the level corresponding to the theoretical dictionary level information and at levels above that level.
[0104] Step 1041: If the match is successful, output the weak password information.
[0105] Step 1042: If the match fails, output the normal password information.
[0106] Reference Figure 2 It also includes a method for classifying dictionary-level information, which includes:
[0107] Step 200: Obtain basic weak password dictionary information and basic dictionary-level information that are not associated with user information.
[0108] The basic weak password dictionary information consists of a dictionary of weak passwords that are commonly used and unrelated to the user, such as 888888, 123456, etc. The basic dictionary level information refers to the level within the basic weak password dictionary information. In this embodiment, the level is set to 1. Alternatively, it can be divided into two dictionaries based on letters and numbers, each with two levels; for example, the dictionary corresponding to 8888 has a level of 1, and the dictionary corresponding to iloveyou has a level of 2.
[0109] Step 201: Analyze the user's own data and related data based on the user information.
[0110] User-specific data refers to information about the user themselves, such as name, date of birth, ID number, and height. User-related data refers to information about individuals associated with the user, such as spouse's name, date of birth, and children's names and dates of birth.
[0111] Step 202: Compile the user's own data information and the user's associated data information according to the preset weak password compilation rules to obtain the user's own weak password information and the user's associated weak password information.
[0112] Weak password creation rules are information about the rules for transforming data into weak passwords. For example, if a person's birthday is December 30, 1992, it will become 19921230 after being created using weak password creation rules. User's own weak password information is information about the user's own data that has been transformed into weak passwords after being created using weak password creation rules. User-associated weak password information is information about the user's associated data that has been transformed into weak passwords after being created using weak password creation rules.
[0113] Step 203: Add the user's own weak password information and the user's associated weak password information to the dictionary to form the user's own weak password dictionary information and the user's associated weak password dictionary information, and set the user's own level information and the user's associated level information, wherein the user's associated level information is higher than the level corresponding to the user's own level information.
[0114] The user's own weak password dictionary information is information from a database containing the user's own weak password information. The user's associated weak password dictionary information is information from a database containing the user's associated weak password information. The user's own level information is the level information corresponding to the user's own weak password dictionary information. Here, it is set to one level higher than the basic dictionary level information by default; for example, the user's own level information is set to level 2. The user's associated level information is the level information corresponding to the user's associated weak password dictionary information. Its level is set to a higher level than the level corresponding to the user's own level information, so it is set to level 3.
[0115] Step 204: Arbitrarily select weak passwords from the basic weak password dictionary information, the user's own weak password dictionary information, and the weak passwords in the dictionary corresponding to the user's associated weak password dictionary information, and combine them to form weak password group information. Then, add the dictionary level information corresponding to the combined content of the weak password group information to obtain the combination level information corresponding to the weak password group information.
[0116] Weak password group information is information formed by combining any two or more weak passwords from the basic weak password dictionary, the user's own weak password dictionary, and the dictionary corresponding to the user's associated weak password dictionary. The combination level information is the level information corresponding to the sum of the dictionary level information corresponding to the combination content of the weak password group information.
[0117] Reference Figure 3 The level classification method corresponding to dictionary-level information further includes:
[0118] Step 300: Select any level and define that level as the current level information.
[0119] The current level information is an arbitrarily selected level, that is, one of the levels obtained by the method in steps 200-204.
[0120] Step 301: Determine whether the number of information types at the current level is greater than one.
[0121] The purpose of this judgment is to determine whether two categories with the same level exist. For example, if the sum of the basic dictionary level information and the user's own level information equals 3, and the user's associated level information is also 3, then the number of categories is greater than 1.
[0122] Step 3011: If there is no more than one, output the current level information normally.
[0123] If not, it means there is only 1 at this time, and there will be no errors when outputting the current level information normally.
[0124] Step 3012: If there is more than one, determine whether one of the current level information is a single-category level information, where single-category level information includes basic dictionary level information, user self-level information, and user associated level information.
[0125] If so, it means that the value is greater than 1, and therefore there must be combination-level information.
[0126] Step 3021: If yes, then increase the level corresponding to the single-category level information and continue to determine whether the number of types of the current level information is greater than one.
[0127] If so, it means that its level is higher than any single category information in the other combined level information. For example, in the case exemplified in step 301, the user association level information is a single category level information, which is more difficult to think of. Therefore, its level is increased by one, that is, the user association level information is level 4, so as to distinguish it from the level of the sum of the basic dictionary level information and the user's own level information.
[0128] Step 3022: If not, remove the same single-category level information from the combined level information and filter out the single-category level information of the highest level, and define the single-category level information of the highest level as the maximum single-category level information.
[0129] If not, it means that all information is at the combined level. In order to distinguish between different levels, it is necessary to determine the single-category level information of the highest level.
[0130] Step 303: Compare and sort the maximum category level information corresponding to all combination level information to obtain the combination category order information.
[0131] The combination category order information is obtained by comparing and sorting all the combination level information according to the highest category level information.
[0132] Step 304: Add levels to the combined level information contained in the current level information in sequence according to the order of the combined category information, and update the current level information.
[0133] When the maximum category level information is the largest among all combined level information, the sequence number is the largest. Then, when the level is increased by adding the combined level information contained in the current level information, the final current level information is the largest.
[0134] It is important to note that since each operation step increases upwards, you can start by selecting from the lowest level. This avoids the need to re-evaluate whether the number of information types at the current level is greater than one when the level decreases.
[0135] Reference Figure 4 Methods for determining theoretical dictionary level information by matching and analyzing dictionary level information and potential protection awareness intensity information stored in the level database include:
[0136] Step 400: Determine the highest level in the dictionary-level information and define that level as the highest level information.
[0137] The method determined is the method in steps 200-304, which will not be elaborated here.
[0138] Step 401: Determine the number of mapping intervals based on the highest level information and the preset maximum protection awareness intensity information.
[0139] The maximum protection awareness level information is the manually set maximum value, for example, 100. The mapping interval quantity information is the number of intervals that need to be divided between protection awareness level 0 and the maximum protection awareness level information. It is determined by converting the number corresponding to the highest level information into the number of intervals. For example, if the levels are 1, 2, and 4, although the highest level information is 4, the quantity is 3, so the mapping interval quantity information is 3.
[0140] Step 402: Classify the weak passwords contained in the dictionary-level information according to the preset classification rules to obtain weak password type information.
[0141] The classification rule information refers to the rules set by humans to categorize weak passwords, such as whether a weak password is classified as a symbol, number, or letter. The weak password type information is the information on the types of weak passwords included in each dictionary-level information.
[0142] Step 403: Calculate the number of weak password types in the same dictionary-level information.
[0143] The information on the number of weak password types refers to the number of weak password types within the same dictionary-level information.
[0144] Step 404: Adjust the consciousness intensity range information corresponding to the number of mapping areas based on the number of weak password types.
[0145] The adjustment method is to equally distribute the information according to the number of weak password types in each dictionary level information, thereby obtaining the corresponding awareness intensity range information. For example, if the types of weak passwords in levels 1, 2 and 3 are 1, 2 and 2 respectively, then the awareness intensity range information of 0-20% is the range of level 1, the awareness intensity range information of 20-60% is the range of level 2, and the awareness intensity range information of 60-100% is the range of level 3.
[0146] Step 405: Establish the mapping relationship between consciousness intensity range information and dictionary level information, and form a level database.
[0147] Step 406: Obtain the current weak password detection result information.
[0148] The current weak password detection result information is the information on whether it is a weak password obtained according to the method in steps 100-1042.
[0149] Step 407: When the current weak password detection result is a weak password, determine whether the consciousness strength range information corresponding to the weak password is accurate.
[0150] The purpose of the judgment is to determine whether it is consistent with the settings. Here, in order to determine whether the consciousness strength range information corresponding to the weak password information is accurate, the previous level setting process will not follow step 104, but will follow all weak passwords. Only after the subsequent basic accuracy is confirmed will the process start to follow step 104.
[0151] Step 4071: If yes, continue using the level database.
[0152] Step 4072: If not, update the level database based on the current weak password detection results.
[0153] Reference Figure 5 Methods for matching weak passwords with password information contained in dictionaries at or above the theoretical dictionary level include:
[0154] Step 500: Parse the password information according to the classification rules to obtain the password type information.
[0155] Password type information refers to the type of password information, such as letters.
[0156] Step 501: Determine whether the password type information is consistent with the weak password type information at or above the level corresponding to the theoretical dictionary level information.
[0157] Step 5011: If they match, then perform a match.
[0158] Step 5012: If there is no match, the weak password type information corresponding to the dictionary-level information is temporarily deleted and not matched.
[0159] Step 502: If the password type information and the weak password type information corresponding to all theoretical dictionary level information and above are inconsistent, output the normal password information directly.
[0160] If all the types are different, then their contents must also be different, which ensures that they are not consistent with the weak passwords in the weak password dictionary, and thus allows the normal password information to be output directly.
[0161] Reference Figure 6 When the password type information and the weak password type information corresponding to all theoretical dictionary level information and above are inconsistent, the methods for directly outputting the normal password information include:
[0162] Step 600: Determine the dictionary level information of the next lower level based on the theoretical dictionary level information, and define the dictionary level information as the adjacent dictionary level information.
[0163] Adjacent dictionary-level information is dictionary-level information that is one level lower than the theoretical dictionary-level information.
[0164] Step 601: Classify the weak passwords contained in the adjacent dictionary-level information according to the classification rules to obtain the adjacent weak password type information.
[0165] The adjacent weak password type information refers to the types of weak passwords contained in the adjacent dictionary-level information. This step can be performed before the initial weak password detection to speed up the detection process.
[0166] Step 602: Determine whether the adjacent weak password type information corresponding to the adjacent dictionary level information exists and the type of password type information.
[0167] Step 6021: If it exists, then match the weak passwords and password information corresponding to the adjacent weak password type information that have been successfully matched.
[0168] This step is to rule out inaccurate weak password identification due to mapping errors between password level and security awareness. However, due to the preceding deep learning process, this step is generally quite accurate, so only the lower-level password is identified.
[0169] Step 6022: If it does not exist, output the normal password information directly.
[0170] Step 603: Update the level database when a match is successful.
[0171] If a match is successful, it means that the mapping relationship is slightly off and deep learning is needed.
[0172] Reference Figure 7 Methods for updating the level database when a match is successful include:
[0173] Step 700: Retrieve the number of adjacent weak password types and the range of adjacent awareness intensity information corresponding to the adjacent dictionary level information from the level database.
[0174] The information on the number of adjacent weak password types refers to the information on the types of weak passwords within the dictionary corresponding to the adjacent dictionary-level information. The information on the intervals of consciousness intensity corresponding to adjacent dictionary-level information refers to the information on the intervals of consciousness intensity corresponding to adjacent dictionary-level information.
[0175] Step 701: Retrieve the theoretical weak password types and quantity information and theoretical awareness intensity range information corresponding to the theoretical dictionary level information from the level database.
[0176] The theoretical weak password type and quantity information refers to the information on the types of weak passwords within the dictionary corresponding to the theoretical dictionary-level information. The theoretical consciousness intensity range information refers to the consciousness intensity range corresponding to the theoretical dictionary-level information.
[0177] Step 702: Divide the adjacent consciousness intensity interval information equally according to the number of adjacent weak password types to determine the equally divided adjacent consciousness intensity interval information.
[0178] The information of equally divided adjacent consciousness intensity intervals is the information of each interval after dividing adjacent consciousness intensity intervals into equal parts according to the number of adjacent weak password types. The method for determining this is to divide the interval length corresponding to the adjacent consciousness intensity interval by the number of adjacent weak password types. Here, it is a virtual interval, not necessarily equally divided; that is, different adjacent weak password types occupy the same actual interval.
[0179] Step 703: Determine the theoretical extension interval information based on the information of adjacent consciousness intensity intervals and the information of equally divided adjacent consciousness intensity intervals.
[0180] The theoretical extension interval information is the interval closest to the theoretical consciousness intensity interval information among adjacent consciousness intensity interval information, and its size is equal to the adjacent consciousness intensity interval information.
[0181] Step 704: Expand and update the theoretical consciousness intensity interval information based on the theoretical extension interval information.
[0182] To improve the accuracy of weak password identification, the theoretical awareness strength range is expanded. This way, when a weak password falls within the theoretical extended range, there is no need to judge the previous process. Instead, it can be directly compared with adjacent dictionary-level information and higher-level dictionaries, thus improving the accuracy of detection.
[0183] Step 705: When the password type information and the adjacent weak password type information are consistent, and the weak password corresponding to the adjacent dictionary level information always matches the password information, delete the theoretical extension interval information in the adjacent awareness strength interval information.
[0184] If the information remains consistent, it indicates that the weak password corresponding to the theoretical extension interval information is actually the content within the dictionary corresponding to the theoretical dictionary level information. In this case, the theoretical extension interval information in the adjacent consciousness intensity interval information is deleted, thereby updating the interval.
[0185] Based on the same inventive concept, embodiments of the present invention provide a website weak password detection system.
[0186] Reference Figure 8 A website weak password detection system, comprising:
[0187] The acquisition module is used to acquire login website information, user information, password information, basic weak password dictionary information, basic dictionary level information, and current weak password detection results.
[0188] A memory used to store a program for controlling a website weak password detection method;
[0189] A control method for detecting weak passwords on websites, where a program in the processor and memory can be loaded and executed by the processor.
[0190] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0191] This invention provides a computer-readable storage medium storing a computer program that can be loaded by a processor and executed as a method for detecting weak website passwords.
[0192] Computer storage media include, for example, USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media that can store program code.
[0193] Based on the same inventive concept, embodiments of the present invention provide a smart terminal, including a memory and a processor, wherein the memory stores a computer program that can be loaded and executed by the processor to perform a website weak password detection method.
[0194] The above are all preferred embodiments of this application and are not intended to limit the scope of protection of this application. Any feature disclosed in this specification (including the abstract and drawings) may be replaced by other equivalent or similar features unless specifically stated otherwise. That is, unless specifically stated otherwise, each feature is only one example of a series of equivalent or similar features.
Claims
1. A website weak password detection method, characterized in that, include: Obtain login website information, user information, and password information; The importance of the login website information and user information is determined by matching and analyzing the importance information stored in the preset website database. This importance information is then defined as the website importance information. Matching analysis is performed based on the protection awareness intensity information, user information, and website importance information stored in the preset evaluation database to determine the protection awareness intensity corresponding to the user information and website importance information, and the protection awareness intensity is defined as the possible protection awareness intensity information. The dictionary level information and the possible protection awareness intensity information stored in the preset level database are matched and analyzed to determine the dictionary level corresponding to the possible protection awareness intensity information, and the dictionary level information is defined as the theoretical dictionary level information. Match weak passwords and password information contained in dictionaries at the theoretical dictionary level and above; If a match is found, output the weak password information. If the match fails, output the normal password information; Methods for determining theoretical dictionary level information by matching and analyzing dictionary level information stored in the level database with potential protection awareness intensity information include: Determine the highest level in the dictionary-level information and define that level as the highest-level information. The number of mapping intervals is determined based on the highest level of information and the preset maximum level of protective awareness. Weak passwords contained in dictionary-level information are classified according to preset classification rules to obtain weak password type information. Calculate the number of weak password types in the same dictionary-level information; Adjust the consciousness intensity range information corresponding to the number of mapping areas based on the number of weak password types; Establish a mapping relationship between consciousness intensity range information and dictionary-level information, and form a level database; Get the current weak password detection results; If the current weak password detection result is a weak password password, determine whether the consciousness strength range information corresponding to the weak password password is accurate. If so, continue using the level database; If not, update the level database based on the current weak password detection results.
2. The website weak password detection method of claim 1, wherein, It also includes a method for classifying dictionary-level information, which includes: Obtain basic weak password dictionary information and basic dictionary-level information that are not associated with user information; Based on user information, analyze the user's own data and user-related data; Based on the preset weak password compilation rules, the user's own data information and the user's associated data information are compiled separately to obtain the user's own weak password information and the user's associated weak password information. Both the user's own weak password information and the user's associated weak password information are added to the dictionary to form the user's own weak password dictionary information and the user's associated weak password dictionary information. The user's own level information and the user's associated level information are set, where the user's associated level information is higher than the level corresponding to the user's own level information. Weak password groups are formed by arbitrarily selecting weak passwords from the basic weak password dictionary, the user's own weak password dictionary, and the dictionary corresponding to the user's associated weak password dictionary. The combination level information corresponding to the combined content of the weak password group information is added together to obtain the combination level information corresponding to the weak password group information.
3. The method of claim 2, wherein the website weak password detection method is characterized by, The level classification method corresponding to dictionary-level information further includes: Select any level and define that level as the current level information; Determine if the number of information types at the current level is greater than one; If there are no more than one, the current level information will be output normally; If there is more than one, then determine whether one of the current level information is a single-category level information, where single-category level information includes basic dictionary level information, user self-level information, and user associated level information; If so, then increase the level corresponding to the single-category level information and continue to determine whether the number of types of the current level information is greater than one; If not, remove the same single-category level information from the combined level information and filter out the single-category level information of the highest level, and define the single-category level information of the highest level as the highest single-category level information. Compare and sort the maximum category level information corresponding to all combination level information to obtain the combination category order information; The levels of the combined level information contained in the current level information are added sequentially according to the order of the combined category information, and the current level information is updated.
4. The website weak password detection method of claim 1, wherein, Methods for matching weak passwords and password information contained in dictionaries at the theoretical dictionary level and above include: The password information is parsed according to the classification rules to obtain the password type information; Determine whether the password type information is consistent with the weak password type information at or above the level corresponding to the theoretical dictionary level information; If they match, then proceed with the matching. If there is a discrepancy, the weak password type information corresponding to that dictionary-level information will be temporarily deleted and not matched. If the password type information and the weak password type information corresponding to all theoretical dictionary level information and above are inconsistent, the normal password information is output directly.
5. The method of claim 4, wherein the website weak password detection method is characterized by, If the password type information and the weak password type information corresponding to all theoretical dictionary level information and above are inconsistent, the methods for directly outputting the normal password information include: Based on the theoretical dictionary level information, determine the dictionary level information of the next lower level, and define the dictionary level information as the adjacent dictionary level information; Weak passwords contained in adjacent dictionary-level information are classified according to classification rules to obtain adjacent weak password type information. Determine whether the adjacent weak password type information and the type of password type information exist in the adjacent dictionary-level information; If they exist, the weak passwords corresponding to the adjacent weak password types that are successfully matched will be matched with the password information. Update the level database if a match is found. If it does not exist, output the normal password information directly.
6. The method of claim 5, wherein the website weak password detection method is characterized by, The methods for updating the level database when a match is successful include: Retrieve the number of adjacent weak password types and the range of adjacent awareness intensity corresponding to adjacent dictionary level information from the level database; Retrieve the theoretical weak password types and quantity information and theoretical awareness intensity range information corresponding to the theoretical dictionary level information from the level database; The adjacent consciousness intensity intervals are divided equally based on the number of adjacent weak password types to determine the equally divided adjacent consciousness intensity intervals. The theoretical extension interval information is determined based on the information of adjacent consciousness intensity intervals and the information of equally divided adjacent consciousness intensity intervals; The theoretical consciousness intensity range information is expanded and updated based on the theoretical extension range information. If the password type information is consistent with the adjacent weak password type information, and the weak password corresponding to the adjacent dictionary level information always matches the password information, then the theoretical extension interval information in the adjacent consciousness strength interval information will be deleted.
7. A website weak password detection system, characterized in that, include: The acquisition module is used to acquire login website information, user information, password information, basic weak password dictionary information, basic dictionary level information, and current weak password detection results. A memory for storing a program of a control method for a website weak password detection method as described in any one of claims 1 to 6; A control method for a website weak password detection method as described in any one of claims 1 to 6, wherein the program in the processor and the memory can be loaded and executed by the processor.
8. Intelligent terminal, characterized in that It includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executed as claimed in any one of claims 1 to 6 for detecting weak website passwords.
9. A computer readable storage medium, characterized in that, The computer program is stored and can be loaded by a processor and executed as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Weak password detection method and device, computer storage medium and equipment
CN112613029A
System and methods for weak authentication data reinforcement
US20090055910A1