You are here: Home Contents V22 N1 V22N1_Hachem.html
Personal tools

Optimizing Password Cracking for Digital Investigations

 

 

Full text
View
Purchase

Source
Journal of Information Systems Security
Volume 22, Number 1 (2026)
Pages 4360
ISSN 1551-0123 (Print)
ISSN 1551-0808 (Online)
Authors
Mohamad Hachem - University of Plymouth, UK
Adam Lanfranchi - University of Plymouth, UK
Nathan Clarke - University of Plymouth, UK
Joakim Kävrestad - Jönköping University, Sweden
Publisher
Information Institute Publishing, Washington DC, USA

 

 

Abstract

Efficient password cracking is a critical aspect of digital forensics, enabling investigators to decrypt protected content during criminal investigations. Traditional password cracking methods, including brute-force, dictionary, and rule-based attacks, face challenges in balancing efficiency with increasing computational complexity. This study explores rule-based optimization strategies to enhance the effectiveness of password cracking while minimizing resource consumption. By analyzing publicly available password datasets, we propose an optimized rule set that reduces computational iterations by approximately 40%, significantly improving the speed of password recovery. Additionally, the impact of national password recommendations were examined – specifically, the UK National Cyber Security Centre’s (NCSC) three-word password guideline – on password security and forensic recovery. Through user-generated password surveys, we evaluate the crackability of threeword passwords using dictionaries of varying common-word proportions. The study underscores the importance of dynamic password cracking strategies that account for evolving user behaviors and policy-driven password structures. Findings contribute to both forensic efficiency and cybersecurity awareness, highlighting the dual impact of password policies on security and investigative capabilities. Future work will focus on refining rule-based cracking techniques and expanding research on password composition trends.

 

 

Keywords

Password Cracking, Digital Forensics, Brute Force, Dictionary Attacks, Optimization.

 

 

References

Biryukov, A., Dinu, D. and Khovratovich, D. (2016). Argon2: new generation of memory-hard functions for password hashing and other applications. [online] Available at: https://orbilu.uni.lu/bitstream/10993/31652/1/Argon2ESP.pdf.

Bosnjak, L., Sres, J. and Brumen, B. (2018). Brute-force and dictionary attack on hashed real-world passwords. Proceedings of the MIPRO Conference.

BNC. 2022. “British National Corpus.” BNC.

Chen, L. (2024). Recommendation for key derivation using pseudorandom functions. [online]

Exterro. 2025. FTK Forensic ToolKit. Exterro. [online]. Available at: https://www.exterro.com/digital-forensics-software/forensic-toolkit

Henry, Gary T. 1990. Practical Sampling. Vol. 21. Sage.

Javed, Abdul Rehman, Waqas Ahmed, Mamoun Alazab, Zunera Jalil, Kashif Kifayat, and Thippa Reddy Gadekallu. 2022. “A Comprehensive Survey on Computer Forensics: State-of-the-Art, Tools, Techniques, Challenges, and Future Directions.” IEEE Access 10:11065–89.

Jin, Sangyoon, and Marc Dupuis. 2024. “Password Usage Behavior of Online Users.” Pp. 1–6 in 2024 Cyber Awareness and Research Symposium (CARS).

Jourdan, Pierre, and Eliana Stavrou. 2019. “Towards Designing Advanced Password Cracking Toolkits: Optimizing the Password Cracking Process.” Pp. 203–8 in Adjunct Publication of the 27th Conference on User Modeling, Adaptation and Personalization, UMAP’19 Adjunct. New York, NY, USA: Association for Computing Machinery.

Kaliski, B. (2000). PKCS #5: Password-Based Cryptography Specification Version 2.0. [online]

Kanta, Aikaterini, Iwen Coisel, and Mark Scanlon. 2024. “A Comprehensive Evaluation on the Benefits of Context Based Password Cracking for Digital Forensics.” Journal of Information Security and Applications 84:103809.

Kanta, A., Iwen Coisel and Scanlon, M. (2023). Harder, better, faster, stronger: Optimising the performance of context-based password cracking dictionaries. Forensic science international. Digital investigation, [online] 44, pp.301507–301507.

Kävrestad, Joakim, Marcus Birath, and Nathan Clarke. 2024. Fundamentals of Digital Forensics: A Guide to Theory, Research and Applications. Cham: Springer International Publishing.

Lee, Kevin, Sten Sjöberg, and Arvind Narayanan. 2022. “Password Policies of Most Top Websites Fail to Follow Best Practices.” Pp. 561–80 in. Oechslin, P. (2003). Making a Faster Cryptanalytic Time-Memory Trade-Off. Lecture Notes in Computer Science, [online] pp.617–630.

OED. 2025. About the OED. [online]. Available at: https://www.oed.com/information/about-the-oed/

Piotr. 2021. “Piotrcki/Wordlist.” [online] Available at: https://github.com/piotrcki/wordlist

Price, E. 2024. Check Your Accounts: 10 Billion Passwords Exposed in Largest Leak Ever. [online] Available at: https://uk.pcmag.com/security/153138/check-youraccounts-10-billion-passwords-exposed-in-largest-leak-ever

Natcorp (2014). British National Corpus. [online] Available at: http://www.natcorp.ox.ac.uk/

NCSC. 2021. Top tips for staying secure online. Available at: https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-randomwords

Tart, Matt, Iain Brodie, Nicholas Patrick-Gleed, Brian Edwards, Kevin Weeks, Robert Moore, and Richard Haseler. 2021. “Cell Site Analysis; Use and Reliability of Survey Methods.” Forensic Science International: Digital Investigation 38:301222.