A brute force attack is a *trial-and-error process* of discovering private information. There are different types of brute force attacks that malicious actors use to guess passwords, including:
- **Simple brute force attacks**: When attackers try to guess a user's login credentials, it’s considered a simple brute force attack. They might do this by entering any combination of usernames and passwords that they can think of until they find the one that works.
- **Dictionary attacks**: Attackers use a list of commonly used passwords and stolen credentials from previous breaches to access a system. These are called “dictionary” attacks because attackers originally used a list of words from the dictionary to guess the passwords, before complex password rules became a common security practice.
Using brute force to access a system can be a tedious and time consuming process, especially when it’s done manually. There are a range of tools attackers use to conduct their attacks.
### Prevention Measures
Some common measures organisations use to prevent brute force attacks and similar attacks from occurring include:
- **Salting and hashing**: Hashing converts information into a unique value that can then be used to determine its integrity. It is a *one-way function*, meaning it is impossible to decrypt and obtain the original text. Salting adds random characters to the passwords.
- **Multi-factor authentication ([[Multi-factor Authentication|MFA]]) and two-factor authentication (2FA)**: MFA is a security measure which requires a user to verify their identity in two or more ways to access a system or network. This verification happens using a combination of authentication factors: a username and password, fingerprints, facial recognition, or a one-time password (OTP) sent to a phone number or email. 2FA is similar to MFA, except it uses only two forms of verification.
- **CAPTCHA and reCAPTCHA**: CAPTCHA stands for *Completely Automated Public Turing test to tell Computers and Humans Apart*. It asks users to complete a simple test that proves they are human. This helps prevent software from trying to brute force a password. reCAPTCHA is a free CAPTCHA service from Google that helps protect websites from bots and malicious software.
- **Password policies**: Organisations use password policies to standardise good password practices throughout the business. Policies can include guidelines on how complex a password should be, how often users need to update passwords, whether passwords can be reused or not, and if there are limits to how many times a user can attempt to log in before their account is suspended.