Attack Probability Calculator
Comprehensive cryptographic attack analysis. Brute force, birthday attacks, side-channel risks, password strength, and key derivation security.
About this calculator
This tool models five distinct cryptographic attack scenarios behind one mode selector, and each mode reads only its own subset of inputs — switching modes changes which fields drive the results entirely. Brute Force Analysis estimates how long an attacker at a given combined hash rate would need to search a key space of a given bit size for a target success probability, then classifies the result into a plain-language feasibility rating from Trivial through Thermodynamically Impossible. Birthday/Collision Attack applies the birthday paradox to hash functions, showing how much smaller the number of attempts needed for a collision is compared to a brute-force search of the full hash space — the square-root relationship that makes hash output size matter more than intuition suggests.
Side-Channel Risk assesses timing, power analysis, cache, and electromagnetic radiation threats based on implementation type and how much physical or measurement access an attacker has, correctly treating an attack vector as not applicable — rather than an unknown, moderate risk — when the required access level isn't present, such as scoring power analysis as zero risk when there's no physical access to measure. Password Attack compares a password's effective entropy against realistic cracking speeds for both fast general-purpose hashes and deliberately slow password-hashing functions, while Key Derivation Security checks whether a chosen KDF's parameters meet current OWASP guidance for resisting GPU and ASIC-accelerated attacks.
Step 1 of 2
How to Use This Calculator
- Choose an Attack Type: Brute Force Analysis, Birthday/Collision Attack, Side-Channel Risk, Password Attack, or Key Derivation Security.
- For Brute Force Analysis, enter the key space in bits, attacker hash rate, parallel devices, and target success probability.
- For Birthday/Collision Attack, enter the hash output size in bits, desired collision probability, and items generated.
- For Side-Channel Risk, select the implementation type, attacker access level, and measurement precision to see timing, power, cache, and EM radiation risk.
- For Password Attack, enter password length, character set size, known patterns, and bcrypt hashing cost.
- For Key Derivation Security, select the KDF algorithm and enter iterations/cost, memory, and parallelism to check OWASP compliance.
- Review the calculated outputs -- such as time to crack, feasibility, collision probability, overall risk, strength rating, or OWASP compliance -- depending on the selected mode.
What each input means
- Attack Type
- Calculation mode to use.
- Key Space (bits)
- AES-128 = 128 bits
- Attack Rate (hashes/sec)
- 1e12 = 1 trillion/sec
- Hash Output (bits)
- MD5=128, SHA-256=256
- Items Generated
- How many hashes created
- Password Length
- Desired password length.
- Character Set Size
- 95 = printable ASCII
- Hashing Cost (bcrypt)
- bcrypt cost factor (10-14)
- Iterations/Cost
- PBKDF2: 100000+, bcrypt: 12, Argon2: 3
- Memory (MB)
- For scrypt/Argon2
- Parallelism
- For Argon2
How this is calculated
Formula
Time = KeySpace / AttackRate | Birthday = √(π/2 × N)Worked example, using the default values
- Identify Input Parameters4 parametersAttack Type = 0, Key Space (bits) = 128, Attack Rate (hashes/sec) = 1000000000000, Parallel Devices = 1 = 19 input(s) provided
- Calculate Time to CrackTime to Crack5391448762278159000 = 5391448762278159000
- Calculate FeasibilityFeasibilityBeyond current technology = Beyond current technology
- Calculate Total Key SpaceTotal Key Space3.402823669209385e+38 = 3.402823669209385e+38
- Calculate Energy CostEnergy Cost4.726143985013035e+21 = $4,726,143,985,013,035,000,000
Engine last updated . Checked against 6 independently-derived tests — how we verify calculators. Built by Paul Gunder, a software engineer, not a licensed financial, medical, or legal professional.
Frequently Asked Questions
Why does switching Attack Type change which inputs and outputs actually matter?
Each of the five modes models a genuinely different kind of attack with its own relevant variables — key space size matters for brute force, hash output size matters for collision attacks, physical access level matters for side channels — so the calculator only reads the inputs specific to whichever mode is currently selected. Inputs left over from a different mode simply aren't referenced by the active calculation.
In Side-Channel Risk mode, why does 'no physical access' score differently from an unrecognized risk level?
Power analysis genuinely requires physical access to measure a device's electrical draw, so when an attacker only has remote access, that attack vector is correctly scored as zero risk rather than an ambiguous default. Treating 'not applicable' the same as 'unknown' would have incorrectly inflated the overall risk score for remote-only threat scenarios where a whole category of physical attacks simply doesn't apply.
Why does the same password show a dramatically different crack time against MD5 versus bcrypt?
MD5 and SHA-256 are fast general-purpose hash functions designed to verify data quickly, which makes them poorly suited for password storage since an attacker can compute billions of guesses per second. bcrypt and Argon2 are deliberately slow, tunable password-hashing functions built specifically to make each guess expensive, which is why the same password entropy translates into a dramatically longer crack time under bcrypt than under a fast general-purpose hash.
What does OWASP Compliant actually check in Key Derivation Security mode?
It compares your chosen KDF algorithm's parameters against minimum thresholds commonly cited in current OWASP password storage guidance — iterations alone for PBKDF2 and bcrypt, memory alone for scrypt, and memory and iterations together only for Argon2id. Falling short of the relevant threshold means the configuration is weaker than currently recommended best practice, even if the algorithm choice itself is otherwise sound.
Related Calculators
The questions that sit next to this one — chosen by subject, including calculators filed under a different category.
Security Tools Calculator
Password strength analysis, crack time estimation, and hash algorithm comparison.
Cryptography & SecurityEncryption Strength Calculator
Complete encryption strength analysis. Key strength, hash functions, cipher modes, post-quantum cryptography, and random number generation.
Cryptography & SecurityBirthday Attack Calculator
Calculate birthday attack parameters, collision probability, time to collision, and attack feasibility for hash functions.
Cryptography & SecuritySecurity Strength Calculator
Calculate overall cryptographic security strength, equivalent key lengths, and security lifetime estimates.
Security ToolsEncryption Strength Calculator
Estimate brute-force time from key length and attacker computing power. Covers symmetric (AES) and asymmetric (RSA) algorithms with quantum threat modeling.
More in Technology & Computing.