Password security warning system
Various embodiments are directed to a password security warning system. An artificial neural network or other types of models may be used to determine whether a password that is created, input, or proposed by a user via an interface includes one or more predictable or typical transformations or combinations of characters derived from user-specific information. Based on the determination, a warning may be provided to the user.
1 . An apparatus comprising:
a memory storing instructions,
one or more processors operably coupled to the memory and configured to execute the instructions that, when executed by the one or more processors, cause the one or more processors to:
determine one or more patterns associated with a user, the one or more patterns comprising at least one of a user-specific pattern of passwords specific to a user, the user-specific pattern not general to a population of users or combinations of at least: first personal information and second personal information different from the first personal information typical or predictable in weak passwords;
process a plurality of lists of blacklisted passwords received from a plurality of service providers, each of the plurality of lists of blacklisted passwords being received from a corresponding service provider of the plurality of service providers, wherein at least one of the plurality of lists of blacklisted passwords is different than other lists of the plurality of lists of blacklisted passwords, wherein at least one of the plurality of service providers is a financial institution;
train a neural network based at least in part on: the user-specific pattern, a plurality of typical or predictable password transformations, the one or more patterns of the combinations of at least the first and second personal information and the plurality of lists of blacklisted passwords, the trained neural network configured to output a plurality of possible password strings unique to a user in response to user-specific information associated with the user provided to the neural network;
receive a password created by the user;
determine whether the password matches at least one possible password string of the plurality of possible password strings based on a threshold match;
provide a warning message that the password is unsafe or insecure in response to the password matching the at least one possible password string, wherein the one or more processors are further caused to:
allow the warning message to be bypassed and the password to be created in response to the threshold match being below a predetermined threshold.
2 . The apparatus of claim 1 , wherein the user-specific information is provided by the user and comprises one or more of the following: a legal first name, a legal middle name, a legal last name, a nickname, a date of birth, a social security number, a home address, a work address, a telephone number, spousal information, and/or a maiden name.
3 . The apparatus of claim 1 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:
perform an Internet search on the user and provide one or more results of the Internet search to the neural network as the user-specific information,
wherein the one or more results of the Internet search comprise information associated with the user from at least one of a social media account, a professional networking profile, a professional profile webpage, a blog, an online dating profile, a public article, or an image.
4 . The apparatus of claim 1 , wherein the plurality of typical or predictable password transformations comprises at least one replacement of a letter with an associated special character.
5 . The apparatus of claim 1 , wherein the plurality of possible password strings output by the neural network comprises at least one or more typical or predictable transformations of the user-specific information and one or more typical or predictable combinations of the user-specific information.
6 . The apparatus of claim 1 , wherein the user-specific pattern is determined based on an identification of a specific pattern used in previous passwords of the user.
7 . The apparatus of claim 1 , wherein the warning message is output to an interface; and
wherein the one or more processors are further caused to:
receive at least one compromised password determined to have been cracked or compromised; and
add the at least one compromised password to at least one of the plurality of lists of blacklisted passwords for updating the training of the neural network to include cracked and compromised passwords.
8 . An apparatus comprising:
at least one memory storing instructions;
one or more processors, operably coupled to the at least one memory, operable to execute the instructions that, when executed by the one or more processors, cause the one or more processors to:
determine a user-specific pattern of passwords specific to a user, the user-specific pattern not general to a population of users;
process a plurality of lists of blacklisted passwords received from a plurality of service providers, each of the plurality of lists of blacklisted passwords being received from a corresponding service provider of the plurality of service providers, wherein at least one of the plurality of lists of blacklisted passwords is different than other lists of the plurality of lists of blacklisted passwords, wherein at least one of the plurality of service providers is a financial institution;
train a neural network based at least in part on the user-specific pattern and the plurality of lists of blacklisted passwords, the trained neural network configured to output a plurality of possible password strings unique to the user based, at least in part, on user-specific information associated with the user provided to the neural network;
receive a password created by the user;
determine whether the password matches at least one possible password string of the plurality of possible password strings based on a threshold match;
output a warning message to an interface indicating the password may be unsafe or insecure; and
allow the warning message to be bypassed and the password to be created in response to the threshold match being below a predetermined threshold.
9 . The apparatus of claim 8 ,
wherein the user-specific pattern is determined based on an identification of a specific pattern used in previous passwords of the user.
10 . The apparatus of claim 8 , the instructions, when executed by the one or more processors, further cause the one or more processors to:
receive at least one compromised password determined to have been cracked or compromised; and
add the at least one compromised password to at least one of the plurality of lists of blacklisted passwords for updating training of the neural network to include cracked and compromised passwords.
11 . The apparatus of claim 8 , wherein the user-specific information is provided by the user and comprises one or more of the following: a legal first name, a legal middle name, a legal last name, a nickname, a date of birth, a social security number, a home address, a work address, a telephone number, spousal information, and/or a maiden name.
12 . The apparatus of claim 8 , wherein the instructions, when executed by the one or more processors, further cause the one or more processors to:
perform an Internet search on the user and provide one or more results of the Internet search to the neural network as the user-specific information,
wherein the one or more results of the Internet search comprise information associated with the user from at least one of a social media account, a professional networking profile, a professional profile webpage, a blog, an online dating profile, a public article, or an image.
13 . The apparatus of claim 8 , wherein the plurality of possible password strings comprises at least one typical or predictable password transformation, the at least one typical or predictable password transformation comprising at least one replacement of a letter with an associated special character.
14 . The apparatus of claim 8 , wherein the plurality of possible password strings output by the neural network comprises at least one typical or predictable transformation of the user-specific information and at least one typical or predictable combination of the user-specific information.
15 . A computer-implemented method, comprising, via at least one computing device:
determining a user-specific pattern of passwords specific to a user, the user-specific pattern not general to a population of users;
processing a plurality of lists of blacklisted passwords received from a plurality of service providers, each of the plurality of lists of blacklisted passwords being received from a corresponding service provider of the plurality of service providers, wherein at least one of the plurality of lists of blacklisted passwords is different than other lists of the plurality of lists of blacklisted passwords, wherein at least one of the plurality of service providers is a financial institution;
training a neural network based at least in part on the user-specific pattern and the plurality of lists of blacklisted passwords, the trained neural network configured to output a plurality of possible password strings unique to the user based, at least in part, on user-specific information associated with the user provided to the neural network;
receiving a password created by the user; and
determining whether the password matches at least one possible password string of the plurality of possible password strings based on a threshold match;
wherein the method further comprises:
outputting a warning message to an interface indicating the password may be unsafe or insecure; and
allowing the warning message to be bypassed and the password to be created in response to the threshold match being below a predetermined threshold.
16 . The method of claim 15 , wherein the user-specific pattern is determined based on an identification of a specific pattern used in previous passwords of the user.
17 . The method of claim 15 , further comprising:
receiving at least one compromised password determined to have been cracked or compromised; and
adding the at least one compromised password to at least one of the plurality of lists of blacklisted passwords for updating training of the neural network to include cracked and compromised passwords.
18 . The method of claim 15 , further comprising:
performing an Internet search on the user and provide one or more results of the Internet search to the neural network as the user-specific information,
wherein the one or more results of the Internet search comprise information associated with the user from at least one of a social media account, a professional networking profile, a professional profile webpage, a blog, an online dating profile, a public article, or an image.
19 . The method of claim 15 , wherein the plurality of possible password strings comprises at least one typical or predictable password transformation, the at least one typical or predictable password transformation comprising at least one replacement of a letter with an associated special character.
20 . The method of claim 15 , wherein the plurality of possible password strings output by the neural network comprises at least one typical or predictable transformation of the user-specific information and at least one typical or predictable combination of the user-specific information.