Unhale, Shreyas Pradeep (2025) Evaluating the Effectiveness of NIST 800-63B Password Policies Against Open-Source Cracking Tools. Masters thesis, Dublin, National College of Ireland.
Preview |
PDF (Master of Science)
Download (2MB) | Preview |
Preview |
PDF (Configuration Manual)
Download (1MB) | Preview |
Abstract
Healthcare organizations are facing an escalating number of credential compromise risks, with average breach costs exceeding 11 million dollars and recovery timelines approaching a year. This study evaluates the effectiveness of modern password policies under AI-enhanced guessing by combining GAN-driven candidate generation with GPU-accelerated cracking. We generated 10,000,000 synthetic candidate passwords across three policy regimes. After quality and policy filtering, 2,000,000 usable samples remained. These were split into two disjoint sets: 1,000,000 hashed for evaluation and 1,000,000 used to train PassGAN to generate attack guesses. The evaluation measured time-to-crack, entropy, and a compliance-adjacent content risk proxy.
We synthesized candidates using breach-derived corpora and healthcare terminology and stratified the evaluation set by entropy into low, medium, and high bands. A hybrid pipeline integrated PassGAN, trained on the 1,000,000 training set, with Hashcat on an RTX 4060 GPU to reflect contemporary adversary capability. Statistical validation, including t-tests, chi-square tests, and effect sizes, assessed differences across policies.
Results show that length-first, NIST-aligned passphrases achieve 30 to 50 percent higher entropy and approximately 90 times longer median time-to-compromise than traditional complexity passwords, while exhibiting substantially lower clinically themed content risk. However, AI-guided guessing materially reduces resistance across all policies. These findings support evidence-based policy modernization emphasizing length, breached-password screening, and reduced user friction, alongside AI-aware assessment to improve practical security outcomes in healthcare identity assurance.
Actions (login required)
![]() |
View Item |
Tools
Tools