返回
Decoding developer password patterns: A comparative analysis of password extraction and selection practices
DOI:10.1016/j.cose.2024.103974.png)
摘要
En 中文
Passwords play a crucial role in authentication, ensuring that only authorised entities can access sensitive information. However, user password choices are often weak and predictable, making them susceptible to cyber-attacks. Additionally, hard-coded credentials in source code can expose organisations and infrastructure to significant risks. This paper explores the patterns of passwords used by developers, examining their similarities to those of typical users. We also investigate the efficacy of large language models (LLMs) in identifying hard-coded credentials in source code. Our findings suggest that developers foster more complex and, hence, more secure password selection patterns than regular users. Nevertheless, they can use worse patterns when the context allows them. The latter, combined with the ample commits in public code repositories containing secrets, exemplifies the need for more targeted awareness campaigns and tighter integration of code security tools in the development lifecycle. Finally, we explore the capacity of LLMs to detect hard-coded credentials, highlighting their differences and limitations.
Keyword:
Pass
DevOps
Hard-coded pass
Source code
DevSecOps
Large language models
AI总结
对已上传原文的论文进行重点信息的提取,主要内容包括:简要概述、研究摘要、背景介绍、关键亮点、图文解析、展望与总结。
期刊
C
IF:
5.4
论文数:
4.6K
被引数:
1.4W
机构
引用论文
A Survey on Large Language Model (LLM) Security and Privacy: The Good, The Bad, and The Ugly关于大型语言模型 (LLM) 安全性和隐私的调查: 好,坏和丑陋
Man vs the machine in the struggle for effective text anonymisation in the age of large language models
SCIENTIFIC REPORTS
IF3.9

