Enhancing Password Security through K-Means Clustering and Entropy-Based Classification using Machine Learning and Deep Learning

Bryan Johanes Rengkung, Neil Royan, Rusdianto Roestam · 2024

Users maintain passwords in order to access systems and accounts, but weak passwords are a severe cybersecurity threat and might cause data breaches. This study proposes a new approach for password strength determination in light of supervised and unsupervised learning with the combination of label assignment through clustering and entropy of password for binary classification. A total of 5,332 passwords, divided into strong and weak classes, are considered, based on unified password rules collected from eight digital service providers and organizations. The passwords are divided into five clusters using K-Means clustering, allowing for feature extraction regarding the classification task. Logistic Regression, Random Forest, and Support Vector Machine models are used and result in over 99% of accuracy, precision, recall, and F1-score; a feedforward neural network shows high flexibility with 99.09% training accuracy and 99.53% test accuracy. Consistently high performance across models speaks of robust generalization of models on unseen data and showcases the models' potential for handling similar instances without overfitting. Differentiating the features, from password entropy to clustering, can improve the predictive performance and contribute towards useful insight in cybersecurity measures related to password strength assessment and identification of weak or compromised passwords. Future work will focus on expanding classes and features, exploring additional classification algorithms, and integrating NLP techniques and user demographics for a more comprehensive approach.

Read the paper · More papers on PaperTik