Directional weak password generation method and device, equipment and medium
By generating prompts containing company and job identifiers and inputting them into the training model, the problem of discrepancies between weak password generation and actual company passwords is solved, enabling efficient penetration testing and security assessment.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-01
- Publication Date
- 2026-03-27
AI Technical Summary
The weak passwords generated by existing technologies differ significantly from the passwords actually used by target companies, which reduces the effectiveness of penetration testing and security assessment.
By obtaining sample weak passwords of the companies to be predicted, prompt words containing company and job identifiers are generated and input into the trained weak password generation model to generate highly targeted weak passwords. The prompt words enable fine-grained control over the style, content, and semantics of the model's output.
It improves the effectiveness of penetration testing and security assessment, generates weak passwords that are more consistent with enterprise characteristics, and increases the efficiency of red team drills and security testing.
Smart Images

Figure CN121750232A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security and artificial intelligence cross-research, and particularly relates to a directional weak password generation method and device, equipment and medium. BACKGROUND
[0002] At present, enterprise network intrusion events occur frequently, many of which are caused by weak password problems. The traditional weak password dictionary is mostly statically constructed, and lacks the ability to perceive the context of a specific enterprise environment. In recent years, the development of large language models has made it possible to generate weak passwords. Among them, weak password refers to a password that is easy to guess or brute force.
[0003] However, the original model is too general and lacks fine control, and cannot learn the naming habits and password patterns specific to an enterprise, resulting in a large difference between the generated weak password and the actual password used by the target enterprise, thereby reducing the effectiveness of penetration testing and security assessment. SUMMARY
[0004] The embodiments of the present application provide a directional weak password generation method, device, equipment and medium, to solve the problem that the weak password generated in the prior art has a large difference from the actual password used by the target enterprise, thereby reducing the effectiveness of penetration testing and security assessment.
[0005] In a first aspect, the embodiments of the present application provide a directional weak password generation method, which comprises: Obtaining a sample weak password saved for a to-be-predicted post in a to-be-predicted enterprise, generating a prompt word containing a first identifier of the to-be-predicted enterprise, a second identifier of the to-be-predicted post, and the sample weak password; Inputting the prompt word, the first identifier and the second identifier into a trained weak password generation model, and generating a target weak password corresponding to the to-be-predicted post in the to-be-predicted enterprise based on the trained weak password generation model.
[0006] In a second aspect, the embodiments of the present application also provide a directional weak password generation device, which comprises: An obtaining module is configured to obtain a sample weak password saved for a to-be-predicted post in a to-be-predicted enterprise, and generate a prompt word containing a first identifier of the to-be-predicted enterprise, a second identifier of the to-be-predicted post, and the sample weak password; A generating module is configured to input the prompt word, the first identifier and the second identifier into a trained weak password generation model, and generate a target weak password corresponding to the to-be-predicted post in the to-be-predicted enterprise based on the trained weak password generation model.
[0007] In a third aspect, the embodiments of the present application further provide an electronic device, which comprises at least a processor and a memory, and the processor is configured to implement the steps of the directional weak password generation method according to any one of the above aspects when executing a computer program stored in the memory.
[0008] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, which stores a computer program, and the computer program is configured to implement the steps of the directional weak password generation method according to any one of the above aspects when executed by a processor.
[0009] In the embodiments of the present application, the sample weak password saved for the to-be-predicted post in the to-be-predicted enterprise is obtained, the prompt word containing the first identifier of the to-be-predicted enterprise, the second identifier of the to-be-predicted post and the sample weak password is generated, the prompt word, the first identifier and the second identifier are input into the trained weak password generation model, and the target weak password corresponding to the to-be-predicted post in the to-be-predicted enterprise is generated based on the trained weak password generation model. By using the prompt word engineering technology, the style, content and semantic of the model output content are finely controlled, so that the highly targeted weak password combination is generated according to the enterprise characteristics, and the effectiveness of the penetration testing and the security evaluation is improved. BRIEF DESCRIPTION OF DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.
[0011] Figure 1 A directional weak password generation process schematic diagram provided by the embodiments of the present application; Figure 2 A directional weak password generation process schematic diagram provided by the embodiments of the present application; Figure 3 A structure schematic diagram of a directional weak password generation device provided by the embodiments of the present application; Figure 4 A structure schematic diagram of an electronic device provided by the embodiments of the present application. DETAILED DESCRIPTION
[0012] In order to make the purpose and embodiments of the present application more clear, the exemplary embodiments of the present application will be described clearly and completely in combination with the drawings in the exemplary embodiments of the present application. Obviously, the described exemplary embodiments are only some embodiments of the present application, but not all the embodiments.
[0013] It should be noted that the brief description of terms in this application is only for the convenience of understanding the embodiments described next, and is not intended to limit the embodiments of the application. Unless otherwise specified, these terms should be understood according to their ordinary and general meanings.
[0014] The terms "first", "second", "third", and the like in the specification and claims of this application and the above-described drawings are used to distinguish similar or like objects or entities, and do not necessarily mean a specific order or sequence, unless otherwise noted. It should be understood that the terms used in this way can be interchanged under appropriate circumstances.
[0015] The terms "include" and "have" and any variations thereof are intended to cover but not exclusive inclusion, for example, a product or device including a series of components does not have to be limited to all components clearly listed, but can include other components not clearly listed or inherent to these products or devices.
[0016] The term "module" refers to any known or later developed hardware, software, firmware, artificial intelligence, fuzzy logic, or a combination of hardware or / and software code capable of performing functions related to the element.
[0017] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the application, and are not limited thereto; although the application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent substitutions for part or all of the technical features; and these modifications or substitutions do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the application.
[0018] For the convenience of explanation, the above description has been made in combination with specific embodiments. However, the above exemplary discussion is not intended to exhaust or limit the embodiments to the specific forms disclosed above. Various modifications and variations can be derived according to the above teachings. The selection and description of the above embodiments are to better explain the principles and practical applications, so that those skilled in the art can better use the embodiments and various different modified embodiments suitable for specific use considerations.
[0019] The embodiment of the application provides a directional weak password generation method, device, equipment and medium, the method comprises the following steps: obtaining a sample weak password saved for a to-be-predicted post in a to-be-predicted enterprise, and generating a prompt word comprising a first identifier of the to-be-predicted enterprise, a second identifier of the to-be-predicted post and the sample weak password; inputting the prompt word, the first identifier and the second identifier into a trained weak password generation model, and generating a target weak password corresponding to the to-be-predicted post in the to-be-predicted enterprise based on the trained weak password generation model. By using the prompt word engineering technology, the style, content and semantics of the model output content are finely controlled, so that a highly targeted weak password combination is generated according to the enterprise characteristics, and the effectiveness of penetration testing and security evaluation is improved.
[0020] Embodiment 1: Figure 1 A directional weak password generation process schematic diagram is provided for the embodiment of the application, and the process comprises the following steps: S101: obtaining a sample weak password saved for a to-be-predicted post in a to-be-predicted enterprise, and generating a prompt word comprising a first identifier of the to-be-predicted enterprise, a second identifier of the to-be-predicted post and the sample weak password.
[0021] The directional weak password generation method provided by the embodiment of the application is applied to an electronic device, and the electronic device can be a personal computer (PC), a server or the like.
[0022] The electronic device saves known real weak passwords corresponding to different enterprises and different posts with high reliability which are collected in advance. In a possible implementation, the weak passwords can also save corresponding industry information (such as finance, education, etc.), organization information and the like.
[0023] Therefore, if the electronic device receives to-be-predicted enterprise information and to-be-predicted post information input by a user, the sample weak password saved for the to-be-predicted post in the to-be-predicted enterprise is searched and obtained from the known real weak passwords corresponding to different enterprises and different posts saved locally, wherein the number of the sample weak passwords can be one or more, which is not specifically limited herein. By
[0024] By using Retrieval-Augmented Generation (RAG), a dynamic few-shot prompt can be constructed, and the diversity and robustness of the prompt can be improved. Specifically, the first identifier of the enterprise to be predicted, the second identifier of the post to be predicted, and the sample weak password are filled into the prompt template at the corresponding positions to generate a prompt containing the first identifier of the enterprise to be predicted, the second identifier of the post to be predicted, and the sample weak password, thereby realizing the construction of a few-shot prompting containing enterprise information input context.
[0025] The first identifier of the enterprise to be predicted can be the enterprise name or a string assigned to the enterprise to be predicted, and the first identifier of the post to be predicted can be the post name or a string assigned to the post to be predicted, which is not specifically limited here.
[0026] For example, the prompt template can satisfy the following format: "Company: {{org}}, Post: {{role}}, Existing password examples: {{pw_list}}, please generate more similar combinations according to the {{rule}} rule"; where org represents the first identifier of the enterprise to be predicted, role represents the second identifier of the post to be predicted, and pw_list represents at least one sample weak password.
[0027] S102: input the prompt, the first identifier, and the second identifier into the trained weak password generation model, and generate the target weak password corresponding to the post to be predicted in the enterprise to be predicted based on the trained weak password generation model.
[0028] The prompt, the first identifier of the enterprise to be predicted, and the second identifier of the post to be predicted are input into the trained weak password generation model in the form of few-shot, and the target weak password corresponding to the post to be predicted in the enterprise to be predicted is generated based on the trained weak password generation model; where the generated target weak password can be used for security testing or red team exercise, which is not specifically limited here. In addition, it should be noted that in the embodiments of the present application, the specific information of the enterprise to be predicted and the post to be predicted is not limited, that is, the trained weak password generation model supports the directional generation of weak passwords for different industries, different sizes of enterprises, and different posts, and has good scalability and adaptability.
[0029] The trained weak password generation model can be a large language model that has already been trained on a general weak password sample to generate weak passwords. Since the prompt words contain sample weak passwords of the positions to be predicted in the company to be predicted, and these sample weak passwords are known and reliable real weak passwords, the language understanding capabilities of the large language model can be used to input the prompt words and the information to be predicted into the trained weak password generation model. This allows the weak password generation model to learn the weak password setting rules of the positions to be predicted in the company to be predicted, understand complex information such as corporate culture and organizational structure, and thus generate weak passwords that are more in line with the actual usage habits of personnel in the relevant industry and positions.
[0030] Furthermore, in one possible implementation, the number of target weak passwords generated by the trained weak password generation model based on the input data (including prompt words, the first identifier of the company to be predicted, and the second identifier of the position to be predicted) can be multiple, such as 80 or 100, without specific limitations. That is, by providing a small number of real-world examples of weak passwords from companies (sample weak passwords of the positions to be predicted within the company to be predicted) in the prompt words as context, the trained weak password generation model can be guided to understand and mimic the specific password setting patterns of the company to be predicted, thereby automatically and on a large scale generating multiple highly targeted and diverse potential weak passwords (target weak passwords).
[0031] In this embodiment, prompt word engineering technology is used to achieve fine control over the style, content, and semantics of the model output content, supporting rapid adaptation and deployment under different model structures, organizational sizes, and industry contexts. This enables the generation of highly targeted weak password combinations based on enterprise characteristics, thereby improving the effectiveness of penetration testing and security assessment.
[0032] Example 2: To improve security testing efficiency, based on the above embodiments, in this embodiment, the prompt word, the first identifier, and the second identifier are input into the trained weak password generation model. Based on the trained weak password generation model, target weak passwords corresponding to the positions to be predicted in the enterprise to be predicted are generated, including: Determine whether the number of times the trained weak password generation model generates weak passwords for input data containing prompt words, first identifier, and second identifier has reached a preset threshold. If not, repeat the step of inputting prompt words, first identifier, and second identifier into the trained weak password generation model until the number of times the trained weak password generation model generates weak passwords for input data reaches the preset threshold. If so, the target weak password is determined based on the weak password combinations generated each time by the trained weak password generation model.
[0033] In order to quickly generate a large number of high-quality candidate weak passwords, in this embodiment of the application, each time a weak password generation model that has been trained is identified to generate a weak password for input data containing a prompt word, a first identifier, and a second identifier, the number of times the weak password generation model has generated a weak password for the input data is counted, and it is determined whether the number of times has reached a preset threshold. If not, the step of inputting the prompt word, the first identifier, and the second identifier into the weak password generation model is repeated until the number of times the weak password generation model has generated a weak password for the input data reaches the preset threshold.
[0034] The preset threshold number of times is a positive integer greater than 1, and the specific value is not restricted here.
[0035] If it is determined that the number of times the trained weak password generation model generates weak passwords for the input data has reached the preset threshold, then the weak password combinations generated by the trained weak password generation model each time are preprocessed and integrated to determine the target weak password obtained after integration.
[0036] The preprocessing includes, but is not limited to, filtering weak password combinations generated each time and evaluating password strength, and no specific restrictions are imposed here.
[0037] Furthermore, it is understandable that, in order to improve the diversity of weak passwords generated by the trained weak password generation model and control the sampling space of weak passwords, in this embodiment, inference parameters such as Temperature and Top-k can be set. Specifically, the Temperature parameter of the trained weak password generation model is set to a higher value to improve the diversity of generated weak passwords; the Top-k parameter of the trained weak password generation model is set to a smaller value, strictly limiting the selection space of the trained weak password generation model before each output of a weak password to the top k candidate weak passwords with the highest probability, ensuring the high quality of the final output weak password and its high relevance to the enterprise context.
[0038] In this embodiment, the trained weak password generation model generates a large number of high-quality, highly targeted weak password combinations based on enterprise characteristics. Compared with traditional dictionary attack methods, it can quickly generate a large number of high-quality candidate passwords, which can be used to simulate the weak password setting habits of real users in red team exercises and security tests, significantly improving the efficiency of red team exercises and security tests.
[0039] Example 3: To improve the quality and usability of the target weak passwords, based on the above embodiments, in this embodiment, the target weak password is determined according to the weak password combinations generated each time by the trained weak password generation model, including: A password strength scoring tool is used to score the password strength of each weak password in each generated weak password combination, and weak passwords with a password strength score lower than the preset score are identified as target weak passwords.
[0040] In this embodiment of the application, in order to improve the quality and practicality of the target weak passwords used for red team drills and security tests, after obtaining the weak password combination generated each time by the trained weak password generation model, the password strength scoring tool connected in the electronic device is used to evaluate the password strength of each weak password in each generated weak password combination, and obtain the password strength score corresponding to each weak password.
[0041] The password strength scoring tool can be zxcvbn.js, etc., and no specific restrictions are made here.
[0042] Understandably, the lower the password strength score of a weak password, the lower its security and the higher the security risk. Therefore, after obtaining the password strength score for each weak password, weak passwords with scores below a preset value are identified as high-risk weak passwords (i.e., easily cracked weak passwords), and these high-risk weak passwords are designated as target weak passwords for subsequent security testing, red team exercises, etc.
[0043] In this embodiment of the application, by evaluating the password strength of each weak password generated by the trained weak password generation model, the weak passwords with lower password strength can be used as target weak passwords for subsequent security tests or red team exercises, thereby improving the quality and practicality of the target weak passwords.
[0044] Example 4: To further improve the quality of target weak passwords, based on the above embodiments, in this embodiment, before using a password strength scoring tool to score the password strength of each weak password in each generated weak password combination, the following is also included: Each weak password in each generated weak password combination is filtered.
[0045] After determining that the number of times the trained weak password generation model generates weak passwords for the input data has reached a preset threshold, in order to improve the quality of the final generated target weak password, in this embodiment of the application, each weak password in each generated weak password combination will be filtered to remove low-quality weak passwords before the password strength scoring tool is used to score the password strength of each weak password in each generated weak password combination.
[0046] The filtering process includes, but is not limited to, deduplicating each weak password in each generated weak password combination and removing invalid format weak passwords.
[0047] In this embodiment of the application, before using a password strength scoring tool to score the password strength of each weak password in each generated weak password combination, each weak password in each generated weak password combination is filtered to remove low-quality weak passwords, thereby further improving the quality of the target weak passwords.
[0048] Example 5: To further improve the quality of target weak passwords, based on the above embodiments, in this embodiment, each weak password in each generated weak password combination is filtered, including: Each weak password combination generated is deduplicated; and / or Delete weak passwords that meet the preset invalid format from each generated weak password combination.
[0049] In order to eliminate duplicate weak passwords, in this embodiment of the application, after determining that the number of times the trained weak password generation model generates weak passwords for the input data has reached a preset threshold, the filtering process for each weak password in each generated weak password combination includes deduplication of each weak password.
[0050] The deduplication process includes: for each weak password, determining whether there is at least one other weak password whose string is exactly the same as the weak password. If so, the weak password is retained, and other weak passwords with exactly the same string are deleted. If not, determining the string similarity between other weak passwords and the weak password, and determining whether there is at least one other weak password whose string similarity is greater than a preset similarity threshold. If so, the weak password is retained, and other weak passwords whose string similarity is greater than the preset similarity threshold are deleted. By removing duplicate weak passwords and filtering similar combinations, sample diversity can be ensured.
[0051] In addition, in order to eliminate low-quality samples, in this embodiment of the application, the filtering process for each weak password in each generated weak password combination may also include: performing compliance checks on each weak password in each generated weak password combination, and deleting weak passwords that meet the preset invalid format.
[0052] In particular, considering that users' passwords will follow certain pre-defined rules within the enterprise when setting them (such as passwords cannot be empty, passwords cannot be all numbers, passwords cannot contain illegal characters, etc.), it can be determined that weak passwords that meet the preset invalid format will be deleted, including but not limited to: using regular expressions to delete weak passwords that are empty strings, using regular expressions to delete invalid weak passwords such as all numbers, deleting weak passwords that contain emojis, and deleting weak passwords that contain full-width characters, so as to standardize the character set range.
[0053] In this embodiment of the application, by deduplicating weak passwords, duplicate samples can be eliminated, ensuring sample diversity; by deleting weak passwords that meet the preset invalid format, low-quality samples can be eliminated, further improving the quality of the target weak passwords.
[0054] Example 6: In order to generate highly targeted weak password combinations based on enterprise characteristics, based on the above embodiments, the process of determining the sample weak passwords stored for the positions to be predicted in the enterprise to be predicted includes at least one of the following in this embodiment: Obtain job information and weak password information from the results of penetration testing conducted on the target company. Obtain job information and weak password information from the results of red team drills targeting the companies to be predicted; Obtain job information and weak password information recorded in the audit logs of the company to be predicted.
[0055] In order to obtain known weak passwords of the company to be predicted, in this embodiment of the application, real sample weak passwords of the company to be predicted can be collected through any one or any combination of the following three methods: Method 1: After conducting a real penetration test on the system of the enterprise to be predicted, a penetration test report containing security vulnerabilities will be obtained. This security vulnerability may contain information such as usernames and corresponding cracked weak passwords. Furthermore, the penetration test report will also contain information such as attack path reproduction information and vulnerability details. The attack path reproduction information and vulnerability details usually indicate which weakness of which position was exploited, i.e., implicitly containing the correspondence between position information and weak passwords. Therefore, in this embodiment of the application, after obtaining the results of the real penetration test conducted on the enterprise to be predicted, the usernames and corresponding weak passwords contained in the test results are read, and the position information corresponding to each weak password is determined based on the attack path reproduction information or vulnerability details contained in the test results. The correspondence between usernames, position information, and weak passwords is then obtained.
[0056] Method Two: After conducting a red team exercise on the system of the enterprise to be predicted, a report containing security vulnerabilities will be obtained. This security vulnerability may contain information such as usernames and corresponding cracked weak passwords. Furthermore, the penetration test report will also contain information such as attack path reproduction information and vulnerability details. The attack path reproduction information and vulnerability details usually indicate which weakness of which position was exploited, i.e., implicitly containing the correspondence between position information and weak passwords. Therefore, in this embodiment of the application, after obtaining the results of the red team exercise against the enterprise to be predicted, the usernames and corresponding weak passwords contained in the exercise results are read, and the position information corresponding to each weak password is determined based on the attack path reproduction information or vulnerability details contained in the exercise results. The correspondence between usernames, position information, and weak passwords is then obtained.
[0057] Method 3: Since the enterprise's audit logs contain login logs, which may include usernames, job information, and corresponding weak passwords, this application embodiment obtains the job information and corresponding weak password information recorded in the audit logs.
[0058] This login log may contain either failed or successful login logs; no specific restrictions are imposed here.
[0059] The weak password samples (i.e., usernames, job information, and weak passwords) obtained through the above three methods will be uniformly organized into a structured format and saved on an electronic device. The structured format includes the following fields: username, weak password, and tags; tags include, but are not limited to, industry, company name (in this case, the name of the company to be predicted), and job information (such as job type).
[0060] When generating weak passwords for the positions to be predicted in the enterprise to be predicted, the sample weak passwords corresponding to the positions to be predicted in the enterprise to be predicted can be determined based on the saved structured sample weak passwords of the enterprise.
[0061] It is understandable that the amount of data obtained through the above three methods may be relatively small, but the data obtained is more representative of the industry. Therefore, in this embodiment of the application, the data collected through the above three methods is used as an example (i.e., containing the enterprise to be predicted, the job to be predicted, and the prompt words of the sample weak password) and input into the trained weak password generation model, which enables the weak password generation model to learn industry habits and output high-quality results.
[0062] In this embodiment, real weak passwords with enterprise characteristics are obtained through actual penetration testing, red team drills, or audit logs, which facilitates the subsequent use of the obtained real weak passwords to generate highly targeted weak password combinations based on enterprise characteristics.
[0063] Example 7: To improve the model's generalization and transfer capabilities under limited sample conditions, based on the above embodiments, the training process of the weak password generation model in this application embodiment includes: Retrieve weak training passwords saved for each position in each enterprise; generate training prompts containing the third identifier of any enterprise, the fourth identifier of the position in that enterprise, and the weak training password. For a training weak password stored for a specific position in any enterprise, the training prompt word, the third identifier, and the fourth identifier are input into the initial weak password generation model to obtain multiple predicted weak passwords and their corresponding predicted probabilities for that specific position in the enterprise, as output by the initial weak password generation model. Based on the training weak password, the multiple predicted weak passwords, and their corresponding predicted probabilities, the loss value corresponding to the training weak password is determined. Based on the loss value corresponding to each trained weak password, the parameters of the preset low-rank matrix of the low-rank adaptation (LoRA) adapter in the initial weak password generation model are updated to obtain the trained weak password generation model.
[0064] In order for the weak password generation model to have the ability to generate weak passwords based on enterprise characteristics, this embodiment of the application also needs to train the weak password generation model. The training process of the weak password generation model is described below: The electronic device stores a training set, including a general training subset and an enterprise-domain training subset. The enterprise-domain training subset stores the correspondence between different enterprises, job positions, and weak passwords. Therefore, to enable the weak password generation model to generate weak passwords based on enterprise characteristics, the electronic device obtains the training weak passwords for each job position within each enterprise from its stored enterprise-domain training subset. For any enterprise among all the enterprises stored in the electronic device, it fills the enterprise's third identifier, the fourth identifier of a specific job position within that enterprise, and the corresponding training weak password into the corresponding positions in the training prompt word template, generating a training prompt word containing the enterprise's third identifier, the fourth identifier of a specific job position within that enterprise, and the corresponding training weak password.
[0065] The training prompt word template can be the same as or slightly different from the prompt word template shown in the above embodiments, and no specific restrictions are imposed here. For example, let's take the case where the training prompt word template is not exactly the same as the prompt word template shown in the above embodiments as an example: Design a supervised fine-tuning (SFT) format instructional training prompt word template, that is, the training prompt word template is a prompt-in-output pair. This format can preserve semantic context, which is beneficial for the initial weak password generation model to understand the combination motivation of weak passwords.
[0066] For example, the training prompt template is: "[Input]: Username: x, Position: x, Industry: x; [Output]: Password Candidate: x", where x represents specific data. Then, by filling the third identifier of the enterprise, the fourth identifier of a certain position in the enterprise, and the corresponding weak training password into the corresponding positions in the training prompt template, the training prompt can be: "[Input]: Username: admin, Position: System Administrator, Industry: Finance; [Output]: Password Candidate: admin2022, root@123, Finance admin@2023".
[0067] After obtaining the training prompt words, for a specific position in any company, the training prompt words, the company's third identifier, and the position's fourth identifier are input into the initial weak password generation model. This yields multiple predicted weak passwords and their corresponding probabilities for that position in the company, output by the initial weak password generation model. Based on the saved loss function, the training weak password, and the multiple predicted weak passwords and their corresponding probabilities output by the initial weak password generation model, the loss value corresponding to the training weak password is determined.
[0068] Based on the loss values corresponding to each weak password, the HuggingFace Transformers ecosystem is used to introduce Quantized Low-Rank Adaptation (QLoRA) technology under the Parameter-Efficient Fine-Tuning (PEFT) framework. This updates the parameters of the preset low-rank matrix of the LoRA adapter in the initial weak password generation model. Specifically, QLoRA is used for parameter injection, inserting adjustable parameters only into the attention layer of the initial weak password generation model while freezing most of the original model weights, resulting in a trained weak password generation model. The preset low-rank matrix can be low-rank matrices A and B (typically set to 8-64) added next to the self-attention layer of the initial weak password generation model. Since only the parameter values of A and B are updated during training, the weights of the initial weak password generation model remain frozen, thus reducing the trainable parameters to less than 1% of the initial weak password generation model. This significantly reduces training resource overhead, making it suitable for deployment in low-resource scenarios and greatly reducing GPU memory requirements.
[0069] After updating the parameters of the preset low-rank matrix of the LoRA adapter in the initial weak password generation model, the performance of the initial weak password generation model can be verified before determining the fully trained weak password generation model. The model verification process is described below: The electronic device stores a verification set containing verification samples from multiple different companies, positions, and corresponding weak passwords. The electronic device retrieves the weak passwords it stores for each position within each company and generates a verification prompt containing the fifth identifier of any company, the sixth identifier of a specific position within that company, and the corresponding weak password. For each verification sample, the corresponding verification prompt, the corresponding fifth identifier, and the sixth identifier are input into an updated initial weak password generation model. Based on this updated model, a predicted weak password is obtained. According to each... The process involves verifying the predicted and verified weak passwords corresponding to each verification sample, determining the perplexity, Top-k hit rate, and structure matching values. If all three values meet the preset verification conditions, training the initial weak password generation model ends, and the model weights and configuration file containing LoRA are saved for subsequent inference. During inference, the adapter weights are loaded onto the frozen initial weak password generation model to obtain the trained weak password generation model, which can then be used for targeted weak password generation. It is understood that the process of determining the perplexity, Top-k hit rate, and structure matching values based on the predicted and verified weak passwords for each verification sample is existing technology and will not be elaborated upon here.
[0070] The Perplexity metric measures the uncertainty of the model's predicted tokens, with a lower Perplexity value indicating a better understanding of the password pattern. The Top-k hit rate metric represents the probability of hitting the real weak password in the first k predictions of the initial weak password generation model, which can be used to test whether the model can accurately predict the real weak password and to simulate the effectiveness of attacks. The structural matching degree metric represents the degree of overlap between the generated result and the real password at the character and substring levels, measuring the structural similarity between the model's generated result and the real weak password, and is used to evaluate semantic closeness. This structural matching degree metric can be either the Bilingual Evaluation Understudy (BLEU) value or the Longest Common Subsequence (Rogue-L) value, without specific restrictions.
[0071] The preset verification conditions include a perplexity index value lower than a preset perplexity threshold, a Top-k hit rate index value higher than a preset hit rate threshold, and a structure matching degree value higher than a preset matching threshold.
[0072] Furthermore, it is understood that the aforementioned initial weak password generation model can be a pre-trained language model that already possesses weak password generation capabilities. Utilizing the language understanding capabilities of a large language model facilitates its subsequent understanding of complex information such as corporate culture and organizational structure, generating passwords that better suit actual usage habits. This supports targeted generation for enterprises of different industries and sizes, exhibiting good scalability and adaptability. Specifically, in this embodiment, the original pre-trained language model has undergone preliminary fine-tuning using a general training subset, enabling it to possess weak password generation capabilities. The preliminary fine-tuning process is described below: The general training subset contains multiple general training samples, and each general training sample contains a username and a corresponding training general weak password. In this embodiment, each general training sample is input into the original pre-trained language model to obtain the predicted general weak passwords corresponding to each general training sample output by the original pre-trained language model. Based on the training general weak passwords and predicted general weak passwords corresponding to each general training sample, the loss value corresponding to each general training sample is determined. Then, according to the loss value corresponding to the general training sample, the parameters of the preset low-rank matrix of the LoRA adapter in the original pre-trained language model are updated to obtain the initial weak password generation model. The process of updating the parameters of the preset low-rank matrix of the LoRA adapter in the original pre-trained language model is similar to the process of updating the parameters of the preset low-rank matrix of the LoRA adapter in the initial weak password generation model provided in the above embodiment, and will not be repeated here.
[0073] Furthermore, to balance performance and computational resource investment, this embodiment selects a pre-trained language model of moderate size suitable for local deployment, and sets training hyperparameters such as the number of training epochs, learning rate, batch size, maximum token length, and LoRA rank to obtain the original pre-trained language model. For example, the pre-trained language model can be Qwen2-7B, LLaMA2-7B, etc.
[0074] Based on the above embodiments, the process of obtaining the training set stored in the electronic device is described below: Collect raw weak passwords from a public cryptographic database and compile them into a list of raw weak passwords; each raw weak password must include at least the weak password field.
[0075] For example, raw weak passwords are collected from publicly leaked password repositories (such as rockyou.txt, HaveIBeenPwned dataset) and public channels such as GitHub; and the common format of the raw weak passwords includes, but is not limited to, "username:password", and the password field exists independently.
[0076] According to the preset extraction rules, the initial weak passwords are extracted from the original weak password list and introduced into the structured extraction script. The unified format is converted into a triple structure: "username|password|tag". The tags include, but are not limited to, industry, company name, job information, etc. If the above tag information is not found in the information related to a weak password, it is determined that the tag corresponding to the weak password is initially empty.
[0077] The preset extraction rules include at least one of the following: extraction based on preset common usernames (such as admin, user, test, guest, etc.) or preset common weak passwords (such as 123456, password, qwerty, company@2020, season + year combination, etc.); extraction based on preset username and weak password combination (such as "[username]:[password]", "[name].[surname]:[birthyear]", etc.); extraction based on the variant username corresponding to the preset common username (such as admin1, administrator, testuser) or the variant weak password corresponding to the preset common weak password (such as password suffix number, year update, etc.).
[0078] Furthermore, considering that some initial weak passwords do not have industry tags, they are treated uniformly as untagged passwords. Therefore, for each initial weak password, it is determined whether the tag information corresponding to the initial weak password is obtained at the same time. If not, the initial weak password is determined as a general training sample in the general training subset to enable the model to learn basic password patterns and syntax rules; if so, the initial weak password is determined as a training sample in the enterprise domain training subset to enable the model to learn enterprise-specific naming habits and password patterns.
[0079] Additionally, it is understandable that penetration testing, red team drills, or audit logs may yield only usernames and corresponding weak passwords, but not corresponding job information. In such cases, the obtained usernames and corresponding weak passwords can be used as general training samples.
[0080] The above embodiments are described below with a specific example. See [link to example]. Figure 2 The flowchart for generating targeted weak passwords includes the following steps: Step 1, Measurement Preparation Process: This includes building a general training subset and building an enterprise domain training subset.
[0081] The construction of the general training subset and the construction of the enterprise domain training subset have been described in the above embodiments and will not be repeated here.
[0082] Step 2, weak password generation model training process: including fine-tuning environment preparation, SFT sample design, fine-tuning training and evaluation.
[0083] The fine-tuning environment preparation involves selecting a pre-trained language model of appropriate size suitable for local deployment; choosing a technology stack and fine-tuning method (i.e., using the HuggingFace Transformers ecosystem and introducing QLoRA technology under the PEFT framework); and setting training hyperparameters such as Epoch, learning rate, Batch Size, Max Token Length, and LoRA rank.
[0084] SFT sample design involves converting samples in the training set into training data in Prompt-In-Output format.
[0085] The fine-tuning training and evaluation process has been described in the above embodiments and will not be repeated here.
[0086] Step 3, Enterprise-Targeted Weak Password Prompt Generation: This includes constructing prompts containing enterprise characteristic context, that is, generating prompts containing the first identifier of the enterprise to be predicted, the second identifier of the position to be predicted, and the sample weak password.
[0087] Step four, targeted combination generation and post-processing: including model inference generation, output control quality assurance, result output, and quality verification.
[0088] Among them, model inference generation means enabling the trained weak password generation model to generate weak passwords multiple times (i.e., a preset number of times threshold) for input data containing prompt words, first identifiers, and second identifiers.
[0089] Output control quality assurance involves filtering out each weak password in each generated weak password combination.
[0090] The output will be the filtered weak passwords.
[0091] Quality verification involves using a password strength scoring tool to score the strength of each weak password after filtering, and identifying weak passwords with a score lower than a preset value as target weak passwords.
[0092] Example 8: Based on the same technical concept and the above embodiments, this application provides a targeted weak password generation device.Figure 3 This application provides a schematic diagram of a targeted weak password generation device, as shown in the embodiments. Figure 3 As shown, the device includes: The acquisition module 301 is used to acquire the sample weak passwords stored for the positions to be predicted in the enterprise to be predicted, and generate a prompt word containing the first identifier of the enterprise to be predicted, the second identifier of the position to be predicted, and the sample weak password. The generation module 302 is used to input the prompt word, the first identifier and the second identifier into the trained weak password generation model, and generate the target weak password corresponding to the position to be predicted in the enterprise to be predicted based on the trained weak password generation model.
[0093] In one possible implementation, the generation module 302 is specifically used to determine whether the number of times the trained weak password generation model generates a weak password for input data containing a prompt word, a first identifier, and a second identifier has reached a preset threshold. If not, the step of inputting the prompt word, the first identifier, and the second identifier into the trained weak password generation model is repeated until the number of times the trained weak password generation model generates a weak password for the input data reaches the preset threshold. If so, the target weak password is determined based on the combination of weak passwords generated by the trained weak password generation model each time.
[0094] In one possible implementation, the generation module 302 is specifically used to use a password strength scoring tool to score the password strength of each weak password in each generated weak password combination, and to determine the weak password with a password strength score lower than a preset score as the target weak password.
[0095] In one possible implementation, the generation module 302 is further configured to filter each weak password in each generated weak password combination before using a password strength scoring tool to score the password strength of each weak password in each generated weak password combination.
[0096] In one possible implementation, the generation module 302 is specifically used to perform deduplication processing on each weak password in each generated weak password combination; and / or delete weak passwords in each generated weak password combination that meet the preset invalid format.
[0097] In one possible implementation, the acquisition module 301 is specifically used to acquire the job information and weak password information contained in the results of penetration testing of the enterprise to be predicted; acquire the job information and weak password information contained in the results of red team exercises of the enterprise to be predicted; and acquire the job information and weak password information recorded in the audit logs corresponding to the enterprise to be predicted.
[0098] In one possible implementation, the targeted weak password generation device further includes a training module 303, used to acquire training weak passwords saved for each position in each enterprise; generate training prompts containing a third identifier of any enterprise, a fourth identifier of the position in that enterprise, and the training weak password; for the training weak password saved for a certain position in any enterprise, input the training prompts, the third identifier, and the fourth identifier into an initial weak password generation model to obtain multiple predicted weak passwords and their corresponding predicted probabilities for that position in that enterprise, output by the initial weak password generation model; determine the loss value corresponding to the training weak password based on the training weak password, the multiple predicted weak passwords, and their corresponding predicted probabilities; and update the parameters of the preset low-rank matrix of the LoRA adapter in the initial weak password generation model based on the loss values corresponding to each training weak password to obtain a trained weak password generation model.
[0099] Example 9: Based on the same technical concept, this application also provides an electronic device. Figure 4 This application provides a schematic diagram of an electronic device structure, such as... Figure 4 As shown, it includes: processor 401, communication interface 402, memory 403 and communication bus 404, wherein processor 401, communication interface 402 and memory 403 communicate with each other through communication bus 404. The memory 403 stores a computer program. When the program is executed by the processor 401, the processor 401 performs the following steps: Obtain the sample weak passwords saved for the positions to be predicted in the enterprise to be predicted, and generate a prompt word containing the first identifier of the enterprise to be predicted, the second identifier of the position to be predicted, and the sample weak passwords. Input the prompt word, the first identifier, and the second identifier into the trained weak password generation model. Based on the trained weak password generation model, generate the target weak passwords corresponding to the positions to be predicted in the enterprise to be predicted.
[0100] In one possible implementation, the processor 401 is specifically configured to determine whether the number of times the trained weak password generation model generates a weak password for input data containing a prompt word, a first identifier, and a second identifier has reached a preset threshold. If not, the step of inputting the prompt word, the first identifier, and the second identifier into the trained weak password generation model is repeated until the number of times the trained weak password generation model generates a weak password for the input data reaches the preset threshold. If so, the target weak password is determined based on the combination of weak passwords generated by the trained weak password generation model each time.
[0101] In one possible implementation, the processor 401 is specifically used to use a password strength scoring tool to score the password strength of each weak password in each generated weak password combination, and to identify weak passwords with password strength scores lower than a preset score as target weak passwords.
[0102] In one possible implementation, the processor 401 is further configured to filter each weak password in each generated weak password combination before using a password strength scoring tool to score the password strength of each weak password in each generated weak password combination.
[0103] In one possible implementation, the processor 401 is specifically configured to perform deduplication processing on each weak password in each generated weak password combination; and / or delete weak passwords in each generated weak password combination that meet a preset invalid format.
[0104] In one possible implementation, the processor 401 is specifically configured to obtain job information and weak password information contained in the results of penetration testing of the enterprise to be predicted; obtain job information and weak password information contained in the results of red team exercises of the enterprise to be predicted; and obtain job information and weak password information recorded in the audit logs corresponding to the enterprise to be predicted.
[0105] In one possible implementation, the processor 401 is specifically configured to: acquire training weak passwords stored for each position in each enterprise; generate training prompts containing a third identifier of any enterprise, a fourth identifier of the position in that enterprise, and the training weak password; input the training prompts, the third identifier, and the fourth identifier into an initial weak password generation model for the training weak password stored for a specific position in any enterprise, thereby obtaining multiple predicted weak passwords and their corresponding predicted probabilities output by the initial weak password generation model for that position in that enterprise; determine the loss value corresponding to the training weak password based on the training weak password, the multiple predicted weak passwords, and their corresponding predicted probabilities; and update the parameters of the preset low-rank matrix of the LoRA adapter in the initial weak password generation model based on the loss values corresponding to each training weak password, thereby obtaining a trained weak password generation model.
[0106] The communication bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This communication bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0107] Communication interface 402 is used for communication between the above-mentioned electronic device and other devices.
[0108] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.
[0109] The processors mentioned above can be general-purpose processors, including central processing units, network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0110] Example 10: Based on the same technical concept, embodiments of this application provide a computer-readable storage medium storing a computer program executable by an electronic device. When the program is run on the electronic device, it causes the electronic device to implement any of the above embodiments.
[0111] The aforementioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in an electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs), etc.
[0112] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0113] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0114] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0115] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0116] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A method for generating targeted weak passwords, characterized in that, The method includes: Obtain the sample weak passwords stored for the positions to be predicted in the enterprise to be predicted, and generate a prompt word containing the first identifier of the enterprise to be predicted, the second identifier of the position to be predicted, and the sample weak passwords. The prompt word, the first identifier, and the second identifier are input into the trained weak password generation model. Based on the trained weak password generation model, the target weak passwords corresponding to the positions to be predicted in the enterprise to be predicted are generated.
2. The method according to claim 1, characterized in that, The step of inputting the prompt word, the first identifier, and the second identifier into the trained weak password generation model, and generating the target weak password corresponding to the position to be predicted in the enterprise to be predicted based on the trained weak password generation model, includes: Determine whether the number of times the trained weak password generation model generates weak passwords for input data containing the prompt word, the first identifier, and the second identifier has reached a preset threshold. If not, repeat the step of inputting the prompt word, the first identifier, and the second identifier into the trained weak password generation model until the number of times the trained weak password generation model generates weak passwords for the input data reaches the preset threshold. If so, the target weak password is determined based on the weak password combinations generated each time by the trained weak password generation model.
3. The method according to claim 2, characterized in that, The step of determining the target weak password based on the weak password combinations generated each time by the trained weak password generation model includes: A password strength scoring tool is used to score the password strength of each weak password in each generated weak password combination, and weak passwords with a password strength score lower than a preset score are identified as target weak passwords.
4. The method according to claim 3, characterized in that, Before using a password strength scoring tool to score the password strength of each weak password in each generated weak password combination, the method further includes: Each weak password in the generated weak password combination is filtered.
5. The method according to claim 4, characterized in that, The weak passwords in each generated weak password combination are filtered, including: Each weak password in the generated weak password combination is deduplicated; and / or Delete weak passwords that meet the preset invalid format from each generated weak password combination.
6. The method according to claim 1, characterized in that, The process of determining weak passwords in the sample of positions to be predicted within the enterprise to be predicted includes at least one of the following: Obtain the job information and weak password information contained in the results of penetration testing conducted on the enterprise to be predicted; Obtain the job information and weak password information contained in the results of the red team exercise targeting the enterprise to be predicted; Obtain the job information and weak password information recorded in the audit logs of the enterprise to be predicted.
7. The method according to any one of claims 1-6, characterized in that, The training process of the weak password generation model includes: Obtain the training weak passwords stored for each position in each enterprise; generate training prompt words containing the third identifier of any enterprise, the fourth identifier of the position in that enterprise, and the training weak passwords; For a training weak password stored for a specific position in any enterprise, the training prompt word, the third identifier, and the fourth identifier are input into an initial weak password generation model to obtain multiple predicted weak passwords and their corresponding predicted probabilities for that specific position in the enterprise, as output by the initial weak password generation model; based on the training weak password, the multiple predicted weak passwords, and their corresponding predicted probabilities, the loss value corresponding to the training weak password is determined. Based on the loss values corresponding to each trained weak password, the parameters of the preset low-rank matrix of the LoRA adapter in the initial weak password generation model are updated to obtain the trained weak password generation model.
8. A targeted weak password generation device, characterized in that, The device includes: The acquisition module is used to acquire sample weak passwords stored for the positions to be predicted in the enterprise to be predicted, and generate a prompt word containing the first identifier of the enterprise to be predicted, the second identifier of the position to be predicted, and the sample weak password. The generation module is used to input the prompt word, the first identifier, and the second identifier into the trained weak password generation model, and generate the target weak password corresponding to the position to be predicted in the enterprise to be predicted based on the trained weak password generation model.
9. An electronic device, characterized in that, The electronic device includes at least a processor and a memory, wherein the processor is configured to execute a computer program stored in the memory to implement the steps of the targeted weak password generation method as described in any one of claims 1-7.
10. A computer storage medium, characterized in that, It stores a computer program executable by an electronic device, which, when run on the electronic device, causes the electronic device to perform the steps of the targeted weak password generation method according to any one of claims 1-7.