Weak password detection method based on deep learning
By building neural network models and optimizing, the problem that existing weak password detection methods rely on fixed rules is solved, and efficient and adaptive detection of passwords is achieved to adapt to new attack strategies.
Patent Information
- Application Number
- CN202411973718.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-13
AI Technical Summary
Existing weak password detection methods often rely on fixed rules and can only work within a limited range and are easily bypassed by new attack strategies.
Weak password detection method based on deep learning is adopted, and by setting up data processing modules, building neural network models, performing model evaluation and optimization, the optimized model is finally deployed to the actual system to realize real-time detection of passwords.
This method can effectively capture the complex characteristics of passwords, adapt to new password patterns and changing attack methods, dynamically adjust detection strategies, without frequent manual intervention or rule updates, and maintain efficient adaptability.
Smart Images

Figure CN119995903A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of weak password detection methods, and in particular to a weak password detection method based on deep learning. Background Art
[0002] With the continuous increase of global Internet facilities, network security has become a major challenge in the field of information technology; users tend to choose simple and easy-to-remember passwords, which leads to the widespread existence of weak passwords, thereby increasing the risk of attacks; attackers can easily obtain sensitive information through dictionary attacks, brute force cracking, etc. In order to protect user data privacy and network security;
[0003] The weak password detection method in the existing technology is rule-based detection, which mainly relies on static rules, such as the password must contain uppercase and lowercase letters, numbers and special characters. These rules are easily bypassed and cannot handle rapidly changing new attacks. Easily cracked passwords are blacklisted in advance and blocked when users set passwords. This method requires continuous updating of the blacklist database to cover newly emerging weak passwords.
[0004] That is, the existing technology has the following technical problems: ordinary weak password detection methods often rely on fixed rules and can only work within a limited range. Therefore, a weak password detection method based on deep learning is proposed to address the above problems. Summary of the invention
[0005] In this embodiment, a weak password detection method based on deep learning is provided to solve the problem that common weak password detection methods in the prior art often rely on fixed rules and can only work within a limited range.
[0006] According to one aspect of the present application, a method for detecting weak passwords based on deep learning is provided, and the method for detecting weak passwords based on deep learning comprises the following steps:
[0007] (1) Setting up a data processing module to collect and preprocess data;
[0008] (2) Build a neural network model, design and train the model;
[0009] (3) Conduct model evaluation and optimization;
[0010] (4) Set up the deployment module to deploy the optimized model to the actual system.
[0011] Furthermore, in step (1), a data processing module is set up, which is responsible for collecting and processing password data, performing preprocessing, cleaning data, removing redundancy and noise, and converting the password into a format suitable for model input.
[0012] Furthermore, in step (1), data collection and preprocessing include the following steps:
[0013] a. Configure the log collector to collect web request logs from different servers, determine the data source, and select a public leaked password database;
[0014] b. Decode URL encoding and special characters in the logs, download and integrate password datasets from different sources;
[0015] c. Filter out obviously irrelevant or invalid entries in the data set;
[0016] d. Remove duplicates from the data to ensure the uniqueness of each password;
[0017] e. Perform data cleaning to remove blanks and records with abnormal formats;
[0018] f. Perform basic statistical analysis on passwords to understand character distribution and length characteristics;
[0019] g. Convert passwords to a unified format;
[0020] h. Encode password characters and generate a character to integer mapping table;
[0021] i. Convert the password character sequence into an integer sequence;
[0022] j. Divide the data set into training set, validation set and test set;
[0023] k. Pad or truncate the password sequence to make it of the same length;
[0024] l. Mark weak passwords and strong passwords and generate labels;
[0025] m. Standardize and normalize the data;
[0026] n. End.
[0027] Furthermore, in step (2), a neural network model is built using Keras to capture password features.
[0028] Furthermore, in step (2), building a neural network model includes the following steps:
[0029] a. Initialize Keras and set the random seed to keep the results reproducible;
[0030] b. Select an appropriate model framework;
[0031] c. Add an Embedding layer to convert the password vector into a dense representation;
[0032] d. Select the corresponding neural network layer and add it to capture the sequence characteristics;
[0033] e. Set the number of neurons and activation function of the hidden layer;
[0034] f. Add Dropout layer to prevent overfitting;
[0035] g. Add Dense layers as needed to increase model complexity;
[0036] h. Set the output layer to binary classification and use the sigmoid activation function;
[0037] i. Select a suitable loss function;
[0038] j. Select the optimizer and set the learning rate;
[0039] k. Compile the model and check the output shape of each layer;
[0040] l. Load the training dataset and set the batch size;
[0041] m. Set the number of training rounds and verification frequency;
[0042] n. Call the fit method to start training and record the loss and accuracy;
[0043] o. Save the best model through EarlyStopping and ModelCheckpoint;
[0044] p. End.
[0045] Furthermore, in step (3), the model is evaluated and optimized to ensure that it performs well on the validation set and the test set. The model is evaluated using accuracy, precision, and recall indicators, and the model performance is further optimized by adjusting hyperparameters, increasing the size of the data set, and changing the network architecture.
[0046] Furthermore, in step (3), model evaluation and optimization includes the following steps:
[0047] a. Load the trained model;
[0048] b. Use the validation set to calculate the initial accuracy of the model;
[0049] c. Evaluate the confusion matrix of the model to analyze classification errors;
[0050] e. Calculate precision, recall and F1 score;
[0051] f. Use ROC curve and AUC value to evaluate classification performance;
[0052] g. Check the change graph of loss and accuracy during training;
[0053] h. Identify overfitting or underfitting phenomena;
[0054] i. Select appropriate optimization scheme according to evaluation indicators;
[0055] j. Adjust model hyperparameters;
[0056] k. Increase or decrease the number of network layers and modify the model architecture;
[0057] l. Retrain the model and record performance changes;
[0058] m. Use data enhancement technology to improve data diversity;
[0059] n. Use cross-validation to evaluate model performance;
[0060] o. Determine the final model and save it for production use;
[0061] p. End.
[0062] Furthermore, in step (4), the optimized model is integrated into the actual system to achieve real-time detection of the password.
[0063] Furthermore, in step (4), the model deployment includes the following steps:
[0064] a. Determine the deployment platform;
[0065] b. Choose a suitable framework to build API services;
[0066] c. Write API interfaces to realize data interaction with external systems;
[0067] d. Load the final model and ensure that it depends on the configuration of the environment;
[0068] e. Write a prediction script to convert the input password data into the model input format;
[0069] f. Ensure that the API supports concurrency and fast response;
[0070] g. Add error handling mechanism to improve system stability;
[0071] h. Use Docker containerized models and services to improve portability;
[0072] i. Conduct security tests on services to prevent potential vulnerabilities;
[0073] j. Set up a monitoring system to continuously track the performance of the service;
[0074] k. Prepare automation scripts to achieve continuous integration and deployment;
[0075] l. Evaluate the response time of the service under different loads;
[0076] m. Adjust server configuration or expand resources as needed;
[0077] n. Write user guides and API documentation;
[0078] o. Deploy online and conduct final global functional testing;
[0079] p. End.
[0080] Through the above-mentioned technical solution of the present application, the present application utilizes deep learning technology and the deep neural network implemented by Keras to effectively capture the complex features of the password and realize efficient detection, thereby solving the problem that the traditional weak password detection method often relies on fixed rules, can only work within a limited range, and is easily bypassed by new attack strategies; the present application builds a neural network model, the model has the characteristics of automatic learning, can adapt to new password patterns and ever-changing attack methods, and can dynamically adjust the detection strategy by continuously updating the data set and retraining the model, without frequent manual intervention or rule updates, thereby maintaining efficient adaptive capabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0081] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0082] Figure 1 This is a schematic diagram of the overall process of an embodiment of the present application;
[0083] Figure 2 A schematic diagram of the data collection and preprocessing process of an embodiment of the present application;
[0084] Figure 3 A schematic diagram of a process for building a neural network model according to an embodiment of the present application;
[0085] Figure 4 A schematic diagram of a process of model evaluation and optimization according to an embodiment of the present application;
[0086] Figure 5 A flowchart of model deployment according to an embodiment of the present application. DETAILED DESCRIPTION
[0087] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.
[0088] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present application described here. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0089] In the present application, the terms "upper", "lower", "left", "right", "front", "back", "top", "bottom", "inner", "outer", "middle", "vertical", "horizontal", "lateral", "longitudinal" and the like indicate positions or positional relationships based on the positions or positional relationships shown in the drawings. These terms are mainly used to better describe the present application and its embodiments, and are not used to limit the indicated devices, elements or components to have a specific orientation, or to be constructed and operated in a specific orientation.
[0090] In addition, some of the above terms may be used to express other meanings in addition to indicating orientation or positional relationship. For example, the term "on" may also be used to express a certain dependency or connection relationship in some cases. For those of ordinary skill in the art, the specific meanings of these terms in this application can be understood according to specific circumstances.
[0091] In addition, the terms "installed", "set", "provided with", "connected", "connected", and "socketed" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral structure; it can be a mechanical connection, or an electrical connection; it can be a direct connection, or an indirect connection through an intermediate medium, or it can be an internal connection between two devices, elements, or components. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to specific circumstances.
[0092] See also Figure 1-5As shown, a method for detecting weak passwords based on deep learning is provided, and the method for detecting weak passwords based on deep learning comprises the following steps:
[0093] (1) Setting up a data processing module to collect and preprocess data;
[0094] (2) Build a neural network model, design and train the model;
[0095] (3) Conduct model evaluation and optimization;
[0096] (4) Set up the deployment module to deploy the optimized model to the actual system.
[0097] Through the above technical solution, the deep neural network implemented by Keras in this application can effectively capture the complex features of passwords and achieve efficient detection, solving the problem that traditional weak password detection methods often rely on fixed rules, can only work within a limited range, and are easily bypassed by new attack strategies; this application builds a neural network model, which has the characteristics of automatic learning and can adapt to new password patterns and ever-changing attack methods. By continuously updating the data set and retraining the model, the detection strategy can be dynamically adjusted without frequent manual intervention or rule updates, thereby maintaining efficient adaptive capabilities.
[0098] In the step (1), a data processing module is set up, which is responsible for collecting and processing password data, performing preprocessing, cleaning data, removing redundancy and noise, and converting the password into a format suitable for model input;
[0099] In step (1), data collection and preprocessing include the following steps:
[0100] a. Configure the log collector to collect web request logs from different servers, determine the data source, and select a public leaked password database;
[0101] b. Decode URL encoding and special characters in the logs, download and integrate password datasets from different sources;
[0102] c. Filter out obviously irrelevant or invalid entries in the data set;
[0103] d. Remove duplicates from the data to ensure the uniqueness of each password;
[0104] e. Perform data cleaning to remove blanks and records with abnormal formats;
[0105] f. Perform basic statistical analysis on passwords to understand character distribution and length characteristics;
[0106] g. Convert passwords to a unified format;
[0107] h. Encode password characters and generate a character to integer mapping table;
[0108] i. Convert the password character sequence into an integer sequence;
[0109] j. Divide the data set into training set, validation set and test set;
[0110] k. Pad or truncate the password sequence to make it of the same length;
[0111] l. Mark weak passwords and strong passwords and generate labels;
[0112] m. Standardize and normalize the data;
[0113] n. End;
[0114] In the step (2), a neural network model is built using Keras to capture password features;
[0115] In step (2), building a neural network model includes the following steps:
[0116] a. Initialize Keras and set the random seed to keep the results reproducible;
[0117] b. Select an appropriate model framework;
[0118] c. Add an Embedding layer to convert the password vector into a dense representation;
[0119] d. Select the corresponding neural network layer and add it to capture the sequence characteristics;
[0120] e. Set the number of neurons and activation function of the hidden layer;
[0121] f. Add Dropout layer to prevent overfitting;
[0122] g. Add Dense layers as needed to increase model complexity;
[0123] h. Set the output layer to binary classification and use the sigmoid activation function;
[0124] i. Select a suitable loss function;
[0125] j. Select the optimizer and set the learning rate;
[0126] k. Compile the model and check the output shape of each layer;
[0127] l. Load the training dataset and set the batch size;
[0128] m. Set the number of training rounds and verification frequency;
[0129] n. Call the fit method to start training and record the loss and accuracy;
[0130] o. Save the best model through EarlyStopping and ModelCheckpoint;
[0131] p. end;
[0132] In step (3), the model is evaluated and optimized to ensure that it performs well on the validation set and the test set. The model is evaluated using accuracy, precision, and recall indicators. The model performance is further optimized by adjusting hyperparameters, increasing the size of the data set, and changing the network architecture.
[0133] In step (3), model evaluation and optimization includes the following steps:
[0134] a. Load the trained model;
[0135] b. Use the validation set to calculate the initial accuracy of the model;
[0136] c. Evaluate the confusion matrix of the model to analyze classification errors;
[0137] e. Calculate precision, recall and F1 score;
[0138] f. Use ROC curve and AUC value to evaluate classification performance;
[0139] g. Check the change graph of loss and accuracy during training;
[0140] h. Identify overfitting or underfitting phenomena;
[0141] i. Select appropriate optimization scheme according to evaluation indicators;
[0142] j. Adjust model hyperparameters;
[0143] k. Increase or decrease the number of network layers and modify the model architecture;
[0144] l. Retrain the model and record performance changes;
[0145] m. Use data enhancement technology to improve data diversity;
[0146] n. Use cross-validation to evaluate model performance;
[0147] o. Determine the final model and save it for production use;
[0148] p. End;
[0149] In the step (4), the optimized model is integrated into the actual system to achieve real-time detection of the password;
[0150] In step (4), the model deployment includes the following steps:
[0151] a. Determine the deployment platform;
[0152] b. Choose a suitable framework to build API services;
[0153] c. Write API interfaces to realize data interaction with external systems;
[0154] d. Load the final model and ensure that it depends on the configuration of the environment;
[0155] e. Write a prediction script to convert the input password data into the model input format;
[0156] f. Ensure that the API supports concurrency and fast response;
[0157] g. Add error handling mechanism to improve system stability;
[0158] h. Use Docker containerized models and services to improve portability;
[0159] i. Conduct security tests on services to prevent potential vulnerabilities;
[0160] j. Set up a monitoring system to continuously track the performance of the service;
[0161] k. Prepare automation scripts to achieve continuous integration and deployment;
[0162] l. Evaluate the response time of the service under different loads;
[0163] m. Adjust server configuration or expand resources as needed;
[0164] n. Write user guides and API documentation;
[0165] o. Deploy online and conduct final global functional testing;
[0166] p. End.
[0167] The above description is only the preferred embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method for detecting weak passwords based on deep learning, characterized in that: The weak password detection method based on deep learning includes the following steps: (1) Setting up a data processing module to collect and preprocess data; (2) Build a neural network model, design and train the model; (3) Conduct model evaluation and optimization; (4) Set up the deployment module to deploy the optimized model to the actual system.
2. A method for detecting weak passwords based on deep learning according to claim 1, characterized in that: In the step (1), a data processing module is set up, which is responsible for collecting and processing password data, performing preprocessing, cleaning data, removing redundancy and noise, and converting the password into a format suitable for model input.
3. A method for detecting weak passwords based on deep learning according to claim 1, characterized in that: In step (1), data collection and preprocessing include the following steps: a. Configure the log collector to collect web request logs from different servers, determine the data source, and select a public leaked password database; b. Decode URL encoding and special characters in the logs, download and integrate password datasets from different sources; c. Filter out obviously irrelevant or invalid entries in the data set; d. Remove duplicates from the data to ensure the uniqueness of each password; e. Perform data cleaning to remove blanks and records with abnormal formats; f. Perform basic statistical analysis on passwords to understand character distribution and length characteristics; g. Convert passwords to a unified format; h. Encode password characters and generate a character to integer mapping table; i. Convert the password character sequence into an integer sequence; j. Divide the data set into training set, validation set and test set; k. Pad or truncate the password sequence to make it of the same length; l. Mark weak passwords and strong passwords and generate labels; m. Standardize and normalize the data; n. End.
4. The method for detecting weak passwords based on deep learning according to claim 1, characterized in that: In the step (2), Keras is used to build a neural network model to capture password features.
5. The method for detecting weak passwords based on deep learning according to claim 1, characterized in that: In step (2), building a neural network model includes the following steps: a. Initialize Keras and set the random seed to keep the results reproducible; b. Select an appropriate model framework; c. Add an Embedding layer to convert the password vector into a dense representation; d. Select the corresponding neural network layer and add it to capture the sequence characteristics; e. Set the number of neurons and activation function of the hidden layer; f. Add Dropout layer to prevent overfitting; g. Add Dense layers as needed to increase model complexity; h. Set the output layer to binary classification and use the sigmoid activation function; i. Select a suitable loss function; j. Select the optimizer and set the learning rate; k. Compile the model and check the output shape of each layer; l. Load the training dataset and set the batch size; m. Set the number of training rounds and verification frequency; n. Call the fit method to start training and record the loss and accuracy; o. Save the best model through EarlyStopping and ModelCheckpoint; p. End.
6. The method for detecting weak passwords based on deep learning according to claim 1, characterized in that: In step (3), the model is evaluated and optimized to ensure good performance on the validation set and the test set. The model is evaluated using accuracy, precision, and recall indicators. The model performance is further optimized by adjusting hyperparameters, increasing the size of the data set, and changing the network architecture.
7. The method for detecting weak passwords based on deep learning according to claim 1, characterized in that: In step (3), model evaluation and optimization includes the following steps: a. Load the trained model; b. Use the validation set to calculate the initial accuracy of the model; c. Evaluate the confusion matrix of the model to analyze classification errors; e. Calculate precision, recall and F1 score; f. Use ROC curve and AUC value to evaluate classification performance; g. Check the change graph of loss and accuracy during training; h. Identify overfitting or underfitting phenomena; i. Select appropriate optimization scheme according to evaluation indicators; j. Adjust model hyperparameters; k. Increase or decrease the number of network layers and modify the model architecture; l. Retrain the model and record performance changes; m. Use data enhancement technology to improve data diversity; n. Use cross-validation to evaluate model performance; o. Determine the final model and save it for production use; p. End.
8. The method for detecting weak passwords based on deep learning according to claim 1, characterized in that: In the step (4), the optimized model is integrated into the actual system to achieve real-time detection of the password.
9. The method for detecting weak passwords based on deep learning according to claim 1, characterized in that: In step (4), the model deployment includes the following steps: a. Determine the deployment platform; b. Choose a suitable framework to build API services; c. Write API interfaces to realize data interaction with external systems; d. Load the final model and ensure that it depends on the configuration of the environment; e. Write a prediction script to convert the input password data into the model input format; f. Ensure that the API supports concurrency and fast response; g. Add error handling mechanism to improve system stability; h. Use Docker containerized models and services to improve portability; i. Conduct security tests on services to prevent potential vulnerabilities; j. Set up a monitoring system to continuously track the performance of the service; k. Prepare automation scripts to achieve continuous integration and deployment; l. Evaluate the response time of the service under different loads; m. Adjust server configuration or expand resources as needed; n. Write user guides and API documentation; o. Deploy online and conduct final global functional testing; p. End.