NORMA eResearch @NCI Library

Evaluating the Effectiveness of NIST 800-63B Password Policies Against Open-Source Cracking Tools

Unhale, Shreyas Pradeep (2025) Evaluating the Effectiveness of NIST 800-63B Password Policies Against Open-Source Cracking Tools. Masters thesis, Dublin, National College of Ireland.

[thumbnail of Master of Science]
Preview
PDF (Master of Science)
Download (2MB) | Preview
[thumbnail of Configuration Manual]
Preview
PDF (Configuration Manual)
Download (1MB) | Preview

Abstract

Healthcare organizations are facing an escalating number of credential compromise risks, with average breach costs exceeding 11 million dollars and recovery timelines approaching a year. This study evaluates the effectiveness of modern password policies under AI-enhanced guessing by combining GAN-driven candidate generation with GPU-accelerated cracking. We generated 10,000,000 synthetic candidate passwords across three policy regimes. After quality and policy filtering, 2,000,000 usable samples remained. These were split into two disjoint sets: 1,000,000 hashed for evaluation and 1,000,000 used to train PassGAN to generate attack guesses. The evaluation measured time-to-crack, entropy, and a compliance-adjacent content risk proxy.

We synthesized candidates using breach-derived corpora and healthcare terminology and stratified the evaluation set by entropy into low, medium, and high bands. A hybrid pipeline integrated PassGAN, trained on the 1,000,000 training set, with Hashcat on an RTX 4060 GPU to reflect contemporary adversary capability. Statistical validation, including t-tests, chi-square tests, and effect sizes, assessed differences across policies.

Results show that length-first, NIST-aligned passphrases achieve 30 to 50 percent higher entropy and approximately 90 times longer median time-to-compromise than traditional complexity passwords, while exhibiting substantially lower clinically themed content risk. However, AI-guided guessing materially reduces resistance across all policies. These findings support evidence-based policy modernization emphasizing length, breached-password screening, and reduced user friction, alongside AI-aware assessment to improve practical security outcomes in healthcare identity assurance.

Item Type: Thesis (Masters)
Supervisors:
Name
Email
Salahuddin, Jawad
UNSPECIFIED
Uncontrolled Keywords: Password security; AI-enhanced guessing; PassGAN; NIST SP 800-63B; Healthcare identity assurance; CTGAN; Entropy
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
Q Science > QH Natural history > QH301 Biology > Methods of research. Technique. Experimental biology > Data processing. Bioinformatics > Artificial intelligence
Q Science > Q Science (General) > Self-organizing systems. Conscious automata > Artificial intelligence
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
R Medicine > Healthcare Industry
Divisions: School of Computing > Master of Science in Cyber Security
Depositing User: Ciara O'Brien
Date Deposited: 19 Aug 2026 15:44
Last Modified: 19 Aug 2026 15:44
URI: https://norma.ncirl.ie/id/eprint/9556

Actions (login required)

View Item View Item