Analysis of password authentication strength
Abstract
The article develops an approach to assessing the strength of password authentication based on numerical, probabilistic, and entropy metrics. For this purpose, mathematical expressions were formulated to determine the time required to crack a password using brute-force methods, as well as the probability of successfully guessing it within its validity period. The proposed formulas made it possible to identify the key parameters affecting password security, including length, alphabet size, character complexity, and password lifetime. Particular attention is paid to the analysis of password entropy according to Shannon and heuristic entropy recommended by NIST. Based on these approaches, criteria were established for determining whether a password can be considered resistant to attacks. To confirm the research results, examples of entropy calculations for different password lengths and alphabets were provided, along with statistical data on password usage in Google services. This made it possible to reveal that a significant number of users continue to employ overly simple combinations that are highly vulnerable to attacks. In addition, the article presents a comparative analysis of traditional approaches and modern methods for improving security. In particular, the integration of classical password-based methods with new technologies, such as graphical passwords and steganographic mechanisms based on digital watermarks, is proposed. This approach makes it possible to enhance the robustness of authentication systems and provide additional protection against unauthorized access to information resources.
Problems in programming 2026; 3: 29-35
Keywords
Full Text:
PDFReferences
Bonneau, J. (2012). The science of guessing: Analyzing an anonymized corpus of 70 million passwords. In 2012 IEEE Symposium on Security and Privacy (pp. 538–552). IEEE.
Florêncio, D., & Herley, C. (2007). A large-scale study of web password habits. In Proceedings of the 16th International Conference on World Wide Web (pp. 657–666). ACM.
Shay, R., Komanduri, S., Durity, A. L., Huh, P. S., Mazurek, M. L., Segreti, S. M., Ur, B., Bauer, L., Christin, N., & Cranor, L. F. (2014). Can long passwords be secure and usable? In Proceedings of the SIGCHI Conference on Human Factors in Computing Systems. pp. 2927–2936. ACM.
Biddle, R., Chiasson, S., & Van Oorschot, P. C. (2012). Graphical passwords: Learning from the first twelve years. ACM Computing Surveys, 44(4).
Johnson, N. F., Duric, Z., & Jajodia, S. (2001). Information Hiding: Steganography and Watermarking—Attacks and Countermeasures. Boston, MA: Kluwer Academic Publishers.
Cox, I. J., Miller, M. L., Bloom, J. A., Fridrich, J., & Kalker, T. (2007). Digital Watermarking and Steganography (2nd ed.). Burlington, MA: Morgan Kaufmann.
Petitcolas, F. A. P., Anderson, R. J., & Kuhn, M. G. (1999). Information hiding—A survey. Proceedings of the IEEE, 87(7), 1062–1078.
Harris, S., & Maymi, F. J. (2021). CISSP All-in One Exam Guide, 9th ed. New York, NY: McGraw-Hill Education.
Stolitnyi, O. V. (2019). Information protection in computer systems and networks. Kyiv: Igor Sikorsky Kyiv Polytechnic Institute.
Markov, A. S., Tsirlov, V. L., & Barabanov, A. V. (2012). Methods for assessing the inadequacy of information protection measures. Moscow: Radio and Communications.
Refbacks
- There are currently no refbacks.








