首页> 外文会议>Network Traffic Measurement and Analysis Conference >A Residential Client-side Perspective on SSL Certificates
【24h】

A Residential Client-side Perspective on SSL Certificates

机译:本地客户端对SSL证书的看法

获取原文

摘要

SSL certificates are a core component of the public key infrastructure that underpins encrypted communication in the Internet. In this paper, we report the results of a longitudinal study of the characteristics of SSL certificate chains presented to clients during secure web (HTTPS) connection setup. Our data set consists of 23B SSL certificate chains collected from a global panel consisting of over 2M residential client machines over a period of 6 months. The data informing our analyses provide perspective on the entire chain of trust, including root certificates, across a wide distribution of client machines. We identify over 35M unique certificate chains with diverse relationships at all levels of the PKI hierarchy. We report on the characteristics of valid certificates, which make up 99.7% of the total corpus. We also examine invalid certificate chains, finding that 93% of them contain an untrusted root certificate and we find they have shorter average chain length than their valid counterparts. Finally, we examine two unintended but prevalent behaviors in our data: the deprecation of root certificates and secure traffic interception. Our results support aspects of prior, scan-based studies on certificate characteristics but contradict other findings, highlighting the importance of the residential client-side perspective.
机译:SSL证书是公钥基础结构的核心组件,它是Internet中加密通信的基础。在本文中,我们报告了在安全Web(HTTPS)连接设置期间向客户端提供的SSL证书链特征的纵向研究结果。我们的数据集由23个SSL证书链组成,这些证书链是在6个月内从一个全球小组收集的,该小组由超过200万个家用客户端计算机组成。通知我们分析的数据提供了对整个客户端计算机范围内整个信任链(包括根证书)的看法。我们在PKI层次的各个级别上识别出超过3500万个具有不同关系的独特证书链。我们报告了有效证书的特征,这些证书占整个语料库的99.7%。我们还检查了无效的证书链,发现其中93%包含不受信任的根证书,并且发现它们的平均链长比有效证书的短。最后,我们检查了数据中两个意外的但普遍的行为:根证书的弃用和安全的流量拦截。我们的结果支持以前基于扫描的证书特征研究的各个方面,但与其他发现相矛盾,突出了住宅客户端观点的重要性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号