Hybrid password cracking method combining neural network model and Hashcat
By combining neural network model and Hashcat, using phased training and multi-modal attack methods, the problem of low password cracking efficiency in the existing technology is solved, and a higher cracking success rate and optimization of computing resources is achieved.
Patent Information
- Application Number
- CN202510592890.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2045-05-09
AI Technical Summary
The prior art relies on a model based on statistical probability in password cracking, lacks generalization, and the speed of deep learning models to generate dictionaries is much lower than the computing speed of Hashcat using GPU resources to crack, resulting in limited cracking efficiency.
Combining the neural network model and Hashcat, through a phased training strategy, the general model is first trained on the complete data set, and the common password pattern and probability distribution are learned, and then fine-tuned high-level parameters with short passwords and long passwords respectively to generate an exclusive model suitable for passwords of different lengths. Use a combination of Hashcat mask attack mode and dictionary attack mode to prioritize testing of high-frequency modes to improve cracking efficiency.
It improves the adaptability of short and long passwords, improves the cracking success rate, optimizes the utilization of computing resources, improves the cracking efficiency of Hashcat, and expands the searchable space.
Smart Images

Figure CN120128344A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of password security, and particularly relates to a hybrid password cracking method combining a neural network model and Hashcat. Background Art
[0002] Text passwords have the advantages of low deployment cost, easy recovery, simple use, easy memorization, no need for complex hardware support, and extremely low deployment cost. Therefore, text passwords are still widely used for identity authentication in network communication and Internet applications. However, the security of text passwords is facing unprecedented challenges. In recent years, database leakage incidents have occurred frequently. These real password data make it possible to guess passwords based on a data-driven mathematical probability model, seriously threatening the security of user passwords. Against the background of frequent data leakage incidents, security researchers use password cracking tools such as Hashcat to deeply analyze users' password habits and help improve password policies. They provide various attack modes, such as dictionary attack, rule attack, mask attack, and combination attack. Users can flexibly select the most suitable attack strategy according to specific security requirements and the characteristics of the target hash. Although each user has different preferences for choosing passwords, through the analysis of a large number of user password datasets, researchers have found that these datasets often have certain statistical characteristics and laws. These laws may be reflected in aspects such as password length distribution, character type distribution, and common character combinations. Based on these statistical characteristics, researchers have proposed various password guessing models, such as those based on probabilistic context-free grammar (PCFG) and Markov models. The PCFG model defines the grammar structure of passwords, decomposes passwords into different grammar units, and estimates the probability distribution of each unit according to training data. The Markov model predicts the possibility of the next character by analyzing the transition probability between characters. These models can capture the generation laws of passwords to a certain extent, generate possible password guessing sets, and provide powerful tools for password strength evaluation and security research. However, this password guessing model based on statistical probability depends on prior knowledge, is affected by the quality of training set data, and lacks generalization.
[0003] With the rapid development of machine learning and deep learning technologies, these technologies have been applied by researchers to password guessing. Password guessing models such as FLA (fast, lean, and accurate) based on recurrent neural networks, PassGAN based on Generative adversarial network (GAN), and PassGPT based on Large Language Model (LLM) have been proposed. Similar to the Markov model, FLA also predicts the next character through an n-order string. The difference is that after training, FLA automatically assigns a small (non-zero) probability to each character in the character table as the prediction result of the input n-order string, which well improves the generalization of the model. PassGAN differentiates between real leaked password datasets and fake passwords generated by the generator, and learns the data distribution of the real password dataset through multiple feedbacks to generate passwords similar to the user's password habits. PassGPT uses the database and text generation capabilities of the large language model to fine-tune GPT2 with a password dataset to generate passwords and achieve password guessing. By training on a large-scale password dataset, these models can learn the complex dependencies and patterns between characters in the password, thereby generating a higher-quality password guessing set. Compared with traditional models, deep learning-based models can usually better capture the semantic and structural features of passwords, improving the accuracy and coverage of guessing. These models can generate a possible password guessing set based on the known password dataset to evaluate password strength or assist in security research. However, the speed of generating dictionaries by these password guessing methods is much lower than the computing speed of Hashcat using GPU resources to crack hash values, resulting in limited cracking efficiency, which poses challenges to improving the efficiency of password guessing. Summary of the Invention
[0004] Technical problem to be solved by the present invention: Aiming at the above problems of the prior art, a hybrid password cracking method combining a neural network model and Hashcat is provided. The present invention aims to combine a neural network model and Hashcat to achieve password cracking to improve the cracking success rate and optimize the utilization of computing resources.
[0005] To solve the above technical problem, the technical solution adopted by the present invention is as follows: A hybrid password cracking method combining a neural network model and Hashcat, comprising the following steps: S101, cleaning the password dataset to remove invalid or abnormal data and extracting available real passwords; S102. Split the password dataset after data cleaning into a short password dataset and a long password dataset; S103. Use the entire password dataset to initially train a neural network model to learn general password patterns and probability distributions to obtain a general neural network model for generating passwords. Freeze the parameters of the lower-layer neurons of the general neural network model, and separately fine-tune and train the high-layer parameters of the general neural network model using the short password dataset and the long password dataset, thereby obtaining two exclusive models applicable to short passwords and long passwords; S104. Use the exclusive model for long passwords to generate real password data for long passwords and add it to the dictionary; use the exclusive model for short passwords to generate real password data for short passwords. Map the real passwords of short passwords to masks according to the mask rules of Hashcat, count the probabilities of the masks, and sort them in descending order to obtain a mask list; S105. For the target password hash value to be cracked, crack the target password hash value through the Hashcat mask attack mode in combination with the mask list, and crack the target password hash value through the Hashcat dictionary attack mode in combination with the dictionary, and return the cracked password.
[0006] Optionally, the data cleaning in step S101 includes: removing duplicate passwords, deleting passwords with incorrect number of digits, passwords containing invalid characters, and deleting some or all of the non-printable ASCII codes.
[0007] Optionally, the splitting of the password dataset after data cleaning into a short password dataset and a long password dataset in step S102 includes: traversing each password in the password dataset after data cleaning, and combining the preset length threshold L, dividing passwords with a length less than or equal to the length threshold L into the short password dataset, and dividing passwords with a length greater than the length threshold L into the long password dataset, and finally splitting the password dataset after data cleaning into a short password dataset and a long password dataset.
[0008] Optionally, when generating long passwords or short passwords in step S104, it includes generating a password dataset according to the scale, and judging whether the generation is completed after generating each scale of password dataset: S201. Initialize the current scale, use the exclusive short password neural network model that has completed training and fine-tuning in this round to generate a dataset composed of real passwords of the current scale, map the real passwords to masks according to the mask rules of Hashcat, and sort them in descending order; S202. Increase the current generated password scale to obtain a new current scale; S203. Use the exclusive short password neural network model that has completed training and fine-tuning in this round to generate a dataset consisting of new real passwords of the current scale, map the real passwords to masks according to the mask rules of Hashcat, and sort them in descending order; S204. Calculate the mask coincidence rate between the mask lists of the new current scale and the previous scale according to the following formula: C = |A ∩ B| / N; where C represents the mask coincidence rate, A is the set of masks extracted from the dataset of the current scale with a probability greater than a specific threshold T, B is the set of masks extracted from the dataset of the previous scale with a probability greater than a specific threshold T, |A ∩ B| represents the number of common elements in the two sets, N is the number of masks in A with a probability greater than the specific threshold T, and the value range of the mask coincidence rate is [0, 1]; S205. Determine whether the mask coincidence rate is greater than the preset threshold R. If it is greater than the preset threshold R, it is determined that the password generation of the current scale is completed, and the process ends and exits; otherwise, jump to step S202.
[0009] Optionally, when using the exclusive model for long passwords to generate real password data for long passwords and add them to the dictionary in step S104, the length of the real password for generating long passwords is [L, L max , where L is the preset length threshold, and L max is the maximum value of the password length.
[0010] Optionally, when using the exclusive model for short passwords to generate real password data for short passwords in step S104, the length of the real password for generating short passwords is [L min , L], where L is the preset length threshold, and L min is the minimum value of the password length.
[0011] Optionally, the preset length threshold is taken as 10.
[0012] Optionally, the maximum value of the password length is 32.
[0013] Optionally, the minimum value of the password length is 6.
[0014] Optionally, when cracking the target password hash value through the Hashcat mask attack mode in combination with the mask list in step S105, it includes preferentially using the masks with higher probability and exceeding the preset threshold in the mask list to crack the target password hash value.
[0015] The present invention proposes an efficient password cracking method by combining a deep learning model with the Hashcat mask attack mode. Compared with the prior art, the present invention can mainly achieve the following beneficial effects: 1. The present invention adopts a phased training strategy. First, a general model is trained on the complete dataset to learn the password patterns and probability distributions. Then, the lower-layer parameters are frozen, and the upper-layer parameters are fine-tuned using short passwords and long passwords respectively to adapt to different lengths of password datasets obtained by users, improve the adaptability to short and long passwords, and adapt to the sparsity of long passwords, thereby enhancing the cracking success rate. After generating short passwords that conform to statistical characteristics, the present invention maps them to mask expressions recognizable by Hashcat and adopts a mask probability sorting algorithm to preferentially test high-frequency patterns, making the cracking process more targeted. This method can not only reproduce the patterns in the password set but also generalize passwords that do not exist in the existing password set but have similar structures, expanding the searchable space and improving the Hashcat cracking efficiency.
[0016] 2. To make full use of the learning ability of the neural network model, the present invention further designs a mask coincidence rate evaluation mechanism to dynamically monitor the change trend of the mask distribution by calculating the coincidence degree of high-probability masks under different generated password scales. When the coincidence rate tends to be stable (i.e., greater than the specified threshold R), it is determined that the model has fully learned the password distribution, and the calculation can be optimized based on the stable mask set, reducing the waste of GPU resources. At the same time, the representativeness and diversity of the generated masks are ensured, and the cracking efficiency is improved. The present invention has significant advantages in both enhancing the generalization ability and fully exploiting the model's feature learning ability for passwords, providing a new solution for efficient password security analysis. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a schematic diagram of the basic process of the method in the embodiment of the present invention.
[0018] Figure 2 It is a schematic diagram of the detailed process of the method in the embodiment of the present invention.
[0019] Figure 3 It is a schematic diagram of the process of data cleaning and data segmentation in the embodiment of the present invention.
[0020] Figure 4 It is a schematic diagram of the process of model construction in the embodiment of the present invention.
[0021] Figure 5 It is a schematic diagram of the process of Hashcat cracking in the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] To make the objectives, technical solutions, and advantages of the present invention clearer and more definite, the present invention will be further described in detail below with reference to specific embodiments. It should be noted that the embodiments described herein are only used to illustrate the content of the present invention and are not intended to limit it.
[0023] As Figure 1 and Figure 2As shown in the figure, the hybrid password cracking method combining a neural network model and Hashcat in this embodiment includes the following steps: S101, Data cleaning: Perform data cleaning on the password dataset to remove invalid or abnormal data and extract available real passwords; S102, Data splitting: Split the password dataset after data cleaning into a short password dataset and a long password dataset; S103, Model construction: Use the entire password dataset to perform initial training on the neural network model to learn the general password patterns and probability distributions to obtain a general neural network model for generating passwords. Freeze the low-level neuron parameters of the general neural network model, and use the short password dataset and the long password dataset respectively to fine-tune and train the high-level parameters of the general neural network model, so as to obtain two exclusive models suitable for short passwords and long passwords; S104, Model application: Use the exclusive model for long passwords to generate real password data for long passwords and add them to the dictionary; use the exclusive model for short passwords to generate real password data for short passwords, map the real passwords for short passwords to masks according to the mask rules of Hashcat, count the probabilities of the masks and sort them in descending order according to the probabilities of the masks to obtain a mask list; according to the mask rules of Hashcat, map lowercase letters to " ", uppercase letters to " ", numbers to " ", special characters to " ", assuming there is a real password of 6 digits, the generated mask is six " "; after mapping to masks, count the probabilities (occurrence frequencies) of each mask. The password distribution usually follows a power-law distribution, that is, a small number of high-frequency masks cover a large number of passwords. Count the occurrence probabilities of each mask and sort them in descending order according to the probabilities; S105, Hashcat cracking: For the target password hash value to be cracked, crack the target password hash value through the Hashcat mask attack mode in combination with the mask list, and crack the target password hash value through the Hashcat dictionary attack mode in combination with the dictionary, and return the cracked password.
[0024] In step S101 of this embodiment, the data cleaning includes: removing duplicate passwords, deleting passwords with incorrect number of digits, passwords containing invalid characters, and deleting some or all of the non-printable ASCII codes. Specifically, Figure 3As shown in the figure, the specific steps included in data cleaning in step S101 of this embodiment are as follows: loading the original password dataset; deduplication: deleting duplicate passwords; filtering invalid passwords, including: deleting passwords with a number of digits not meeting the requirements, passwords containing invalid characters, and deleting non-printable ASCII codes.
[0025] In step S102 of this embodiment, splitting the password dataset after data cleaning into a short password dataset and a long password dataset includes: traversing each password in the password dataset after data cleaning, and combining the preset length threshold L, classifying passwords with a length less than or equal to the length threshold L into the short password dataset, and classifying passwords with a length greater than the length threshold L into the long password dataset, and finally splitting the password dataset after data cleaning into a short password dataset and a long password dataset. The preset length threshold L can be set according to actual needs. For example, as an optional implementation, as Figure 3 shown, in this embodiment, the default value of the preset length threshold L is 10. Passwords with a length less than or equal to 10 are classified into the short password dataset, and passwords with a length greater than 10 are classified into the long password dataset. Finally, the password dataset after data cleaning is split into a short password dataset and a long password dataset. Taking the Rockyou dataset leaked in 2009 as an example, this dataset contains 32.6 million passwords. Combining Figure 3 with data cleaning, first, after performing deduplication on the original Rockyou dataset, the remaining data is 14.34 million passwords. Second, filter invalid data. Considering the current website password rules, delete passwords with less than 6 digits or more than 32 digits, remove invalid characters in the passwords, and delete non-printable ASCII codes. After filtering, 13.99 million passwords remain. Finally, count the password lengths. Here, taking the length boundary set to 10 as an example, separate the passwords with less than or equal to 10 digits and the dataset with more than 10 digits. The short password dataset has 11,603,337 rows, accounting for 82.90%, and the long password dataset has 2,394,106 rows, accounting for 17.10%.
[0026] Figure 4This is a schematic diagram of the process for model construction in this embodiment. It should be noted that the neural network model in this embodiment can adopt the required neural network model according to needs, and both can achieve the training and generation of real passwords. As an alternative implementation, in this embodiment, an existing PassGAN model is used to construct the neural network model, which can be extended to other password guessing models based on neural networks, and is not used to limit the present invention. Load the entire Rockyou password dataset and construct the PassGAN model, where both the generator and the discriminator are composed of 5-layer residual networks (each layer with a dimension of 128). Through the adversarial training of the generator-discriminator, the generator learns the distribution of the training data, and the discriminator distinguishes between real passwords and generated passwords. After iterative training, a general password generation model is obtained. After the training is completed, the lower-layer parameters are frozen to retain their learning ability on the complete dataset. The high-level neurons are fine-tuned using short passwords to obtain a short password model. Here, taking the length setting L = 10 as an example, the short password model is called to generate short passwords, with the minimum length being 6 characters and the maximum length being 10 characters.
[0027] When generating long passwords or short passwords in step S104 of this embodiment, it includes generating a password dataset according to the scale, and after generating each scale of the password dataset, determining whether the generation is completed: S201, Initialize the current scale, use the exclusive short password neural network model that has completed training and fine-tuning in this round to generate a dataset composed of real passwords of the current scale, map the real passwords to masks according to the mask rules of Hashcat, and sort them in descending order; S202, Increase the current generated password scale to obtain a new current scale; S203, Use the exclusive short password neural network model that has completed training and fine-tuning in this round to generate a dataset composed of real passwords of the new current scale, map the real passwords to masks according to the mask rules of Hashcat, and sort them in descending order; S204, Calculate the mask coincidence rate between the new current scale and the mask list of the previous scale according to the following formula: C = |A ∩ B| / N; Among them, C represents the mask coincidence rate. A is the set of masks extracted from the current-scale dataset with probabilities greater than a specific threshold T. B is the set of masks extracted from the previous-scale dataset with probabilities greater than a specific threshold T. |A∩B| represents the number of common elements in the two sets. N is the number of masks in A with probabilities greater than the specific threshold T. The value range of the mask coincidence rate is [0,1]. To evaluate the similarity of mask sets for different password datasets, in this embodiment, the mask coincidence rate is calculated to achieve this. The mask coincidence rate is an index to measure the similarity degree of masks mapped by passwords of different orders of magnitude. Its definition is: extract the mask set A with probabilities greater than a specific threshold (T, default is 0.0001) from the first dataset, and select the first N masks of the same number from the second dataset to form the set B, and calculate the ratio of the size of their intersection to N. S205, determine whether the mask coincidence rate is greater than the preset threshold R. If it is greater than the preset threshold R, it is determined that the password generation of the current scale is completed, and the process ends and exits; otherwise, jump to step S202 to continue the iteration.
[0028] Compare the mask sets generated in the above manner for different password scales (such as 、 、 etc.), and observe the change trend of the mask coincidence rate. When the mask coincidence rate tends to be stable (greater than a certain threshold R, default is 95%), it is determined that the password distribution is stable and the password feature learning ability of the neural network model has been fully exploited. In this embodiment, to evaluate the stability of the mask distribution of different password scale datasets, high-frequency masks with probabilities greater than 0.01% are selected, and their coincidence rates in the mask sets generated by passwords of different orders of magnitude are calculated. If the coincidence rate tends to be stable (greater than the given threshold 95%), it indicates that the neural network model has learned the password distribution characteristics relatively fully. At this time, a smaller-scale mask set can be used for optimization calculation to reduce the calculation overhead; otherwise, a larger-scale password data needs to be generated and remapped into a mask pattern to further optimize the calculation.
[0029] For long passwords, freeze the parameters of the lower-layer neurons that have been trained in the general neural network model, and fine-tune the parameters of the upper layer with the long password dataset to learn the long password features and distribution, and call the fine-tuned exclusive model to generate long passwords. When using the exclusive model of the long password to generate the real password data of the long password and add it to the dictionary in step S104 of this embodiment, the length of the real password for generating the long password is [L,L max , where L is the preset length threshold, and L max is the maximum value of the password length. The maximum value L max of the password length can be set according to actual needs. For example, as an optional implementation method, in this embodiment, the maximum value L max of the password length is 32.
[0030] For short passwords, freeze the trained low-level neuron parameters of the general neural network model, and use the short password dataset to fine-tune and train the high-level parameters to learn the features and distributions of short passwords, and call the fine-tuned exclusive model to generate short passwords. When generating the real password data of the short password using the exclusive model of the short password in step S104 of this embodiment, the length of the real password for generating the short password is [L min , L], where L is a preset length threshold, and L min is the minimum value of the password length. Among them, the minimum value L of the password length min can be set according to actual needs. For example, as an optional implementation, the minimum value L of the password length in this embodiment min is 6.
[0031] Figure 5 This is the flow chart of Hashcat cracking in this embodiment. Refer to Figure 5 , in the password cracking process of the target password hash value (hash value) to be cracked in step S105 of this embodiment, the short password uses mask attack, and the long password uses dictionary attack. The two adopt a parallel cracking strategy, and the two modes are executed in parallel, and all the cracked passwords are returned to the user. When cracking the target password hash value through the Hashcat mask attack mode in combination with the mask list in step S105, it includes preferentially using the masks with higher probability and exceeding the preset threshold in the mask list to crack the target password hash value.
[0032] Suppose there is a set of password pattern sets , where each pattern represents a password structure (such as a combination pattern of numbers, lowercase letters, uppercase letters, etc.). Each pattern has a probability of of occurring in the generated password. Then define the cracking efficiency of the pattern as: ; Among them, is the occurrence probability of the pattern, is the number of possible passwords included in this pattern, is the average time required to crack this pattern. The optimization goal is to maximize the number of cracked passwords within a limited time , and the formula is expressed as: ; Subject to the constraint: , where is the time we can The number of patterns tried internally. For long passwords, since cracking masks with more than 10 digits in the mask pattern takes a lot of time, the dictionary pattern is selected for cracking. Finally, all the successfully cracked passwords are returned.
[0033] To verify the hybrid password cracking method combining the neural network model and Hashcat in this embodiment, this embodiment takes the PassGAN model training on the Rockyou dataset as an example. The scale of the passwords generated by the PassGAN model is , among the comparison results of the mask coincidence rate with a frequency greater than 0.01%, and The coincidence rate of the two mask sets mapped by the generated passwords is 100% after descending order, exceeding the set threshold of 95%. Take The mask set with a probability greater than 0.01% in the mask sets mapped by the generated passwords is used to crack the hash value (password hash value). The coverage rate is 76.19% at 4 hours 44 minutes and 58 seconds, while the coverage rate of the generated passwords only by the PassGAN model is only 15.09%. It can be seen that the coverage rate of the solution of the hybrid password cracking method combining the neural network model and Hashcat in this embodiment is increased by 61.1%, improving the cracking efficiency of Hashcat, and its resource usage can be reduced through the mask coincidence rate.
[0034] The above are only the preferred embodiments of the present invention. The protection scope of the present invention is not limited to the above embodiments. All technical solutions falling within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A hybrid password cracking method combining a neural network model and Hashcat, characterized in that: The steps include: S101, performing data cleaning on the password data set to remove invalid or abnormal data and extract usable real passwords; S102, dividing the password data set after data cleaning into a short password data set and a long password data set; S103, using the entire password data set to perform initial training on the neural network model to learn the common password pattern and probability distribution to obtain a common neural network model for generating passwords, freezing the low-level neuron parameters of the common neural network model, and respectively using the short password data set and the long password data set to perform fine-tuning training on the high-level parameters of the common neural network model, thereby obtaining two exclusive models suitable for short passwords and long passwords; S104, generating a long password using a dedicated model for long passwords and adding the long password to a dictionary; Generate short passwords using a dedicated model for short passwords, map the short passwords to masks according to the masking rules of Hashcat, count the probabilities of the masks, and sort them in descending order according to the probabilities of the masks to obtain a mask list; S105, for the target password hash value to be cracked, the target password hash value is cracked by using the Hashcat mask attack mode in combination with the mask list, and the target password hash value is cracked by using the Hashcat dictionary attack mode in combination with the dictionary, and a successfully cracked password is returned.
2. The hybrid password cracking method combining a neural network model and Hashcat according to claim 1, characterized in that: The data cleaning in step S101 includes: deleting duplicate passwords, deleting passwords that do not meet the required number of digits, deleting passwords containing invalid characters, and deleting part or all of the unprintable ASCII codes.
3. The hybrid password cracking method combining a neural network model and Hashcat according to claim 1, characterized in that: In step S102, the password data set after data cleaning is divided into a short password data set and a long password data set, including: traversing each password in the password data set after data cleaning, combining with a preset length threshold L, dividing the passwords with a password length less than or equal to the length threshold L into the short password data set, dividing the passwords with a password length greater than the length threshold L into the long password data set, and finally dividing the password data set after data cleaning into the short password data set and the long password data set.
4. The hybrid password cracking method combining a neural network model and Hashcat according to claim 1, characterized in that: When generating a long password or a short password in step S104, it includes generating a password data set according to the scale, and determining whether the generation is completed after generating a password data set of each scale: S201, initialize the current scale, use the dedicated short password neural network model that has been trained and fine-tuned in this round to generate a data set consisting of real passwords of the current scale, map the real passwords into masks according to the mask rules of Hashcat and arrange them in descending order; S202, increasing the current generated password scale to obtain a new current scale; S203, using the dedicated short password neural network model that has been trained and fine-tuned in this round to generate a new data set consisting of real passwords of the current scale, mapping the real passwords to masks according to the masking rules of Hashcat and arranging them in descending order; S204, calculating the mask overlap rate between the mask lists of the new current scale and the previous scale according to the following formula: C = |A∩B| / N; Where C represents the mask overlap rate, A is the set of masks extracted from the current scale data set with a probability greater than a specific threshold T, B is the set of masks extracted from the previous scale data set with a probability greater than a specific threshold T, |A∩B| represents the number of common elements in the two sets, N is the number of masks in A with a probability greater than a specific threshold T, and the range of the mask overlap rate is [0,1]; S205, determining whether the mask overlap rate is greater than a preset threshold R, if it is greater than the preset threshold R, determining that the password generation of the current scale is completed, ending and exiting; Otherwise, jump to step S202.
5. The hybrid password cracking method combining a neural network model and Hashcat according to claim 3, characterized in that: In step S104, when the real password data of the long password is generated using the dedicated model of the long password and added to the dictionary, the length of the real password generated is [L, L max ], where L is the preset length threshold, L max The maximum password length.
6. The hybrid password cracking method combining a neural network model and Hashcat according to claim 5, characterized in that: In step S104, when the short password dedicated model is used to generate the real password of the short password, the length of the real password generated by the short password is [L min ,L], where L is the preset length threshold, L min The minimum password length.
7. The hybrid password cracking method combining a neural network model and Hashcat according to claim 6, characterized in that: The preset length threshold value is 10.
8. The hybrid password cracking method combining a neural network model and Hashcat according to claim 7, characterized in that: The maximum password length is 32.
9. The hybrid password cracking method combining a neural network model and Hashcat according to claim 8, characterized in that: The minimum value of the password length is 6.
10. The hybrid password cracking method combining a neural network model and Hashcat according to claim 1, characterized in that: In step S105, when the target password hash value is cracked by using the Hashcat mask attack mode in combination with the mask list, the mask in the mask list with a higher probability and exceeding a preset threshold is preferentially used to crack the target password hash value.
Citation Information
Patent Citations
Disrupting Password Attack Using Compression
US20140331063A1
System and process for generating passwords or password guesses
US20200074073A1