home/glossary/Guessing Entropy

Guessing Entropy

nounid 2692·updated Aug 30, 2026
verified· unreviewed

A measure of the difficulty that an Attacker has to guess the average password used in a system. In this document, entropy is stated in bits. When a password has n-bits of guessing entropy then an attacker has as much difficulty guessing the average password as in guessing an n-bit random quantity. The attacker is assumed to know the actual password frequency distribution.

MWE

Attested in

No recorded attestations. They are written when an MWE tagging stage is completed, stamped with the pack version and the document’s digest.

Classifications

Entity Type

Metric0%rule-basedmulti_axis_classifier_low_confidence.v1

Sensitivity

85%llm-generatedllm:claude-haiku-4-5

Information Class

90%llm-generatedllm:claude-haiku-4-5

Variants

plural
Guessing Entropies
possessive
Guessing Entropy's
pluralpossessive
Guessing Entropies'

Framework definitions

NISTIR 7298: Glossary of Key Information Security Terms, Revision 21 senseview framework →
§1
A measure of the difficulty that an Attacker has to guess the average password used in a system. In this document, entropy is stated in bits. When a password has n-bits of guessing entropy then an attacker has as much difficulty guessing the average password as in guessing an n-bit random quantity. The attacker is assumed to know the actual password frequency distribution.
NIST SP 800-631 senseview framework →
§1
A measure of the difficulty that an Attacker has to guess the average password used in a system. In this document, entropy is stated in bits. When a password has n-bits of guessing entropy then an attacker has as much difficulty guessing the average password as in guessing an n-bit random quantity. The attacker is assumed to know the actual password frequency distribution.
Legacy lexicon import1 senseview framework →
§1 · legacy_primary
A measure of the difficulty that an Attacker has to guess the average password used in a system. In this document, entropy is stated in bits. When a password has n-bits of guessing entropy then an attacker has as much difficulty guessing the average password as in guessing an n-bit random quantity. The attacker is assumed to know the actual password frequency distribution.
DR-088 backfill from the noun definition column

Outgoing relationships

No outgoing triples
This term is not the subject of any RDF-style relationship yet.

Incoming relationships

No incoming triples
No other term currently asserts a relationship to this one.