{"id":"https://openalex.org/W3158562336","doi":"https://doi.org/10.1016/j.fsidi.2021.301186","title":"How viable is password cracking in digital forensic investigation? Analyzing the guessability of over 3.9 billion real-world accounts","display_name":"How viable is password cracking in digital forensic investigation? Analyzing the guessability of over 3.9 billion real-world accounts","publication_year":2021,"publication_date":"2021-07-01","ids":{"openalex":"https://openalex.org/W3158562336","doi":"https://doi.org/10.1016/j.fsidi.2021.301186","mag":"3158562336"},"language":"en","primary_location":{"id":"doi:10.1016/j.fsidi.2021.301186","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2021.301186","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Forensic Science International: Digital Investigation","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.1016/j.fsidi.2021.301186","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5061435270","display_name":"Aikaterini Kanta","orcid":"https://orcid.org/0000-0002-5791-3092"},"institutions":[{"id":"https://openalex.org/I4210118689","display_name":"Joint Research Centre","ror":"https://ror.org/02qezmz13","country_code":"IT","type":"government","lineage":["https://openalex.org/I1320481043","https://openalex.org/I2800387288","https://openalex.org/I4210118689","https://openalex.org/I4210161702"]},{"id":"https://openalex.org/I100930933","display_name":"University College Dublin","ror":"https://ror.org/05m7pjf47","country_code":"IE","type":"education","lineage":["https://openalex.org/I100930933"]}],"countries":["IE","IT"],"is_corresponding":true,"raw_author_name":"Aikaterini Kanta","raw_affiliation_strings":["European Commission, Joint Research Centre (DG JRC), Via Enrico Fermi 2749, 21027, Ispra, VA, Italy","Forensics and Security Research Group, University College Dublin, Ireland"],"affiliations":[{"raw_affiliation_string":"European Commission, Joint Research Centre (DG JRC), Via Enrico Fermi 2749, 21027, Ispra, VA, Italy","institution_ids":["https://openalex.org/I4210118689"]},{"raw_affiliation_string":"Forensics and Security Research Group, University College Dublin, Ireland","institution_ids":["https://openalex.org/I100930933"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034600940","display_name":"Sein Coray","orcid":null},"institutions":[{"id":"https://openalex.org/I1850255","display_name":"University of Basel","ror":"https://ror.org/02s6k3f65","country_code":"CH","type":"education","lineage":["https://openalex.org/I1850255"]}],"countries":["CH"],"is_corresponding":false,"raw_author_name":"Sein Coray","raw_affiliation_strings":["Databases and Information Systems Group, Department of Mathematics and Computer Science, University of Basel, Switzerland"],"affiliations":[{"raw_affiliation_string":"Databases and Information Systems Group, Department of Mathematics and Computer Science, University of Basel, Switzerland","institution_ids":["https://openalex.org/I1850255"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014138734","display_name":"Iwen Coisel","orcid":"https://orcid.org/0000-0001-6571-8441"},"institutions":[{"id":"https://openalex.org/I4210118689","display_name":"Joint Research Centre","ror":"https://ror.org/02qezmz13","country_code":"IT","type":"government","lineage":["https://openalex.org/I1320481043","https://openalex.org/I2800387288","https://openalex.org/I4210118689","https://openalex.org/I4210161702"]}],"countries":["IT"],"is_corresponding":false,"raw_author_name":"Iwen Coisel","raw_affiliation_strings":["European Commission, Joint Research Centre (DG JRC), Via Enrico Fermi 2749, 21027, Ispra, VA, Italy"],"affiliations":[{"raw_affiliation_string":"European Commission, Joint Research Centre (DG JRC), Via Enrico Fermi 2749, 21027, Ispra, VA, Italy","institution_ids":["https://openalex.org/I4210118689"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5033950555","display_name":"Mark Scanlon","orcid":"https://orcid.org/0000-0002-6581-7164"},"institutions":[{"id":"https://openalex.org/I100930933","display_name":"University College Dublin","ror":"https://ror.org/05m7pjf47","country_code":"IE","type":"education","lineage":["https://openalex.org/I100930933"]}],"countries":["IE"],"is_corresponding":false,"raw_author_name":"Mark Scanlon","raw_affiliation_strings":["Forensics and Security Research Group, University College Dublin, Ireland"],"affiliations":[{"raw_affiliation_string":"Forensics and Security Research Group, University College Dublin, Ireland","institution_ids":["https://openalex.org/I100930933"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5061435270"],"corresponding_institution_ids":["https://openalex.org/I100930933","https://openalex.org/I4210118689"],"apc_list":{"value":2950,"currency":"USD","value_usd":2950},"apc_paid":{"value":2950,"currency":"USD","value_usd":2950},"fwci":5.6718,"has_fulltext":false,"cited_by_count":26,"citation_normalized_percentile":{"value":0.96009748,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":"37","issue":null,"first_page":"301186","last_page":"301186"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11800","display_name":"User Authentication and Security Systems","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9919999837875366,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12553","display_name":"Psychedelics and Drug Studies","score":0.9735000133514404,"subfield":{"id":"https://openalex.org/subfields/3203","display_name":"Clinical Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/password","display_name":"Password","score":0.9521346092224121},{"id":"https://openalex.org/keywords/password-cracking","display_name":"Password cracking","score":0.6677249073982239},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6561940908432007},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5602888464927673},{"id":"https://openalex.org/keywords/authentication","display_name":"Authentication (law)","score":0.5563367009162903},{"id":"https://openalex.org/keywords/password-policy","display_name":"Password policy","score":0.4859405755996704},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.46103930473327637},{"id":"https://openalex.org/keywords/cognitive-password","display_name":"Cognitive password","score":0.4387109875679016},{"id":"https://openalex.org/keywords/password-strength","display_name":"Password strength","score":0.35800379514694214},{"id":"https://openalex.org/keywords/one-time-password","display_name":"One-time password","score":0.33614206314086914},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.33494076132774353},{"id":"https://openalex.org/keywords/geography","display_name":"Geography","score":0.06319913268089294}],"concepts":[{"id":"https://openalex.org/C109297577","wikidata":"https://www.wikidata.org/wiki/Q161157","display_name":"Password","level":2,"score":0.9521346092224121},{"id":"https://openalex.org/C3847113","wikidata":"https://www.wikidata.org/wiki/Q2746524","display_name":"Password cracking","level":5,"score":0.6677249073982239},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6561940908432007},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5602888464927673},{"id":"https://openalex.org/C148417208","wikidata":"https://www.wikidata.org/wiki/Q4825882","display_name":"Authentication (law)","level":2,"score":0.5563367009162903},{"id":"https://openalex.org/C98705547","wikidata":"https://www.wikidata.org/wiki/Q3394687","display_name":"Password policy","level":4,"score":0.4859405755996704},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.46103930473327637},{"id":"https://openalex.org/C23875713","wikidata":"https://www.wikidata.org/wiki/Q5141232","display_name":"Cognitive password","level":5,"score":0.4387109875679016},{"id":"https://openalex.org/C70530487","wikidata":"https://www.wikidata.org/wiki/Q1990841","display_name":"Password strength","level":4,"score":0.35800379514694214},{"id":"https://openalex.org/C89479133","wikidata":"https://www.wikidata.org/wiki/Q1137840","display_name":"One-time password","level":3,"score":0.33614206314086914},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.33494076132774353},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.06319913268089294},{"id":"https://openalex.org/C166957645","wikidata":"https://www.wikidata.org/wiki/Q23498","display_name":"Archaeology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1016/j.fsidi.2021.301186","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2021.301186","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Forensic Science International: Digital Investigation","raw_type":"journal-article"}],"best_oa_location":{"id":"doi:10.1016/j.fsidi.2021.301186","is_oa":true,"landing_page_url":"https://doi.org/10.1016/j.fsidi.2021.301186","pdf_url":null,"source":{"id":"https://openalex.org/S4210178067","display_name":"Forensic Science International Digital Investigation","issn_l":"2666-2817","issn":["2666-2817","2666-2825"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320990","host_organization_name":"Elsevier BV","host_organization_lineage":["https://openalex.org/P4310320990"],"host_organization_lineage_names":["Elsevier BV"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Forensic Science International: Digital Investigation","raw_type":"journal-article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.44999998807907104,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320334701","display_name":"Joint Research Centre","ror":"https://ror.org/04j5wtv36"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":57,"referenced_works":["https://openalex.org/W143386018","https://openalex.org/W150647875","https://openalex.org/W821002660","https://openalex.org/W1466389411","https://openalex.org/W1526870393","https://openalex.org/W2000638898","https://openalex.org/W2048755632","https://openalex.org/W2066345778","https://openalex.org/W2108933516","https://openalex.org/W2111397260","https://openalex.org/W2113266120","https://openalex.org/W2119545418","https://openalex.org/W2127171880","https://openalex.org/W2135359429","https://openalex.org/W2250539671","https://openalex.org/W2254729468","https://openalex.org/W2346878720","https://openalex.org/W2524553946","https://openalex.org/W2680793898","https://openalex.org/W2734150319","https://openalex.org/W2736745396","https://openalex.org/W2739334709","https://openalex.org/W2765667105","https://openalex.org/W2794001933","https://openalex.org/W2795753884","https://openalex.org/W2891820333","https://openalex.org/W2921035272","https://openalex.org/W2930957955","https://openalex.org/W2963532563","https://openalex.org/W2968267813","https://openalex.org/W2982557423","https://openalex.org/W3046647252","https://openalex.org/W3092367696","https://openalex.org/W3105177289","https://openalex.org/W3108713421","https://openalex.org/W3110228208","https://openalex.org/W4205337489","https://openalex.org/W4242289848","https://openalex.org/W4245729972","https://openalex.org/W4286684711","https://openalex.org/W4300999694","https://openalex.org/W4301802532","https://openalex.org/W4315746341","https://openalex.org/W6605803077","https://openalex.org/W6628669832","https://openalex.org/W6662610515","https://openalex.org/W6676951976","https://openalex.org/W6680012636","https://openalex.org/W6691431627","https://openalex.org/W6741502601","https://openalex.org/W6743626266","https://openalex.org/W6749975174","https://openalex.org/W6754852673","https://openalex.org/W6767270520","https://openalex.org/W6769432428","https://openalex.org/W6784495195","https://openalex.org/W6786450119"],"related_works":["https://openalex.org/W2969720675","https://openalex.org/W2596766976","https://openalex.org/W2021087413","https://openalex.org/W2017283799","https://openalex.org/W2953105088","https://openalex.org/W2182949018","https://openalex.org/W2793662593","https://openalex.org/W1978329066","https://openalex.org/W2743151892","https://openalex.org/W1571454820"],"abstract_inverted_index":{"Passwords":[0],"have":[1],"been":[2],"and":[3,23,49,66,93,100],"still":[4],"remain":[5],"the":[6,24,30,64,106,127,141],"most":[7,67,94],"common":[8,95],"method":[9],"of":[10,21,26,40,70,105,116,129,143],"authentication":[11],"in":[12,29,98,131],"computer":[13],"systems.":[14],"These":[15],"systems":[16],"are":[17],"therefore":[18],"privileged":[19],"targets":[20],"attackers,":[22],"number":[25],"data":[27,42],"breaches":[28],"last":[31],"few":[32],"years":[33],"attests":[34],"to":[35,73,120],"that.":[36],"A":[37],"detailed":[38],"analysis":[39,69,88,139],"such":[41],"can":[43],"provide":[44,136],"insight":[45,125],"on":[46,91,126,140],"password":[47,132],"trends":[48],"patterns":[50,96],"users":[51],"follow":[52],"when":[53],"they":[54],"create":[55],"a":[56,103,114],"password.":[57,112],"To":[58],"this":[59,61],"end,":[60],"paper":[62],"presents":[63],"largest":[65],"comprehensive":[68],"real-world":[71,145],"passwords":[72,99],"date":[74],"\u2013":[75],"associated":[76],"with":[77,102],"over":[78],"3.9":[79],"billion":[80],"accounts":[81],"from":[82],"Have":[83],"I":[84],"Been":[85],"Pwned.":[86],"This":[87],"includes":[89],"statistics":[90],"use":[92],"found":[97],"innovates":[101],"breakdown":[104],"constituent":[107],"fragments":[108,118],"that":[109],"make":[110],"each":[111],"Furthermore,":[113],"classification":[115],"these":[117,144],"according":[119],"their":[121],"semantic":[122],"meaning,":[123],"provides":[124],"role":[128],"context":[130],"selection.":[133],"Finally,":[134],"we":[135],"an":[137],"in-depth":[138],"guessability":[142],"passwords.":[146]},"counts_by_year":[{"year":2025,"cited_by_count":6},{"year":2024,"cited_by_count":7},{"year":2023,"cited_by_count":7},{"year":2022,"cited_by_count":6}],"updated_date":"2026-03-17T09:09:15.849793","created_date":"2025-10-10T00:00:00"}
