Comparative analysis of hashing algorithm implementations available on the Spring Security framework
Keywords:
Cyber Attacks, Cybersecurity, HashingAbstract
Passwords are commonly the main target of malicious attackers, and therefore, when stored, techniques and processes are applied with the goal of increasing security and decreasing the risk of a successful attack. The Spring Security framework notoriously provides implementations of the hashing algorithms Bcrypt, Scrypt, PBKDF2, and Argon2. This paper aims to compare the standard implementations of these hashing algorithms, and aid in choosing a hashing algorithm in a computational resource utilization context. By using the Java Microbenchmark Harness (JMH), memory consumption and average execution time of the hashing of common passwords was analyzed, along with the usage of Hashcat to evaluate dictionary attack resistance. Results showed Bcrypt has the lowest memory consumption and lowest execution time, while Scrypt has the greatest memory consumption and greatest dictionary attack resistance, and Argon2 consumed significantly more memory than Bcrypt, though with similar dictionary attack resistance. PBKDF2 showed the slowest execution time and the weakest dictionary attack resistance.