首页> 外文会议>ASE/IEEE International Conference on Social Computing >The Potential of an Individualized Set of Trusted CAs: Defending against CA Failures in the Web PKI
【24h】

The Potential of an Individualized Set of Trusted CAs: Defending against CA Failures in the Web PKI

机译:个性化的可信CAS集的潜力:防止Web PKI中的CA故障

获取原文

摘要

Abstract-The security of most Internet applications relies on underlying public key infrastructures (PKIs) and thus on an ecosystem of certification authorities (CAs). The pool of PKIs responsible for the issuance and the maintenance of SSL certificates, called the Web PKI, has grown extremely large and complex. Herein, each CA is a single point of failure, leading to an attack surface, the size of which is hardly assessable. This paper approaches the issue if and how the attack surface can be reduced in order to minimize the risk of relying on a malicious certificate. In particular, we consider the individualization of the set of trusted CAs. We present a tool called Rootopia, which allows to individually assess the respective part of the Web PKI relevant for a user. Our analysis of browser histories of 22 Internet users reveals, that the major part of the PKI is completely irrelevant to a single user. On a per user level, the attack surface can be reduced by more than 90%, which shows the potential of the individualization of the set of trusted CAs. Furthermore, all the relevant CAs reside within a small set of countries. Our findings confirm that we unnecessarily trust in a huge number of CAs, thus exposing ourselves to unnecessary risks. Subsequently, we present an overview on our approach to realize the possible security gains.
机译:摘要 - 大多数互联网申请的安全性依赖于潜在的公钥基础设施(PKI),从而依赖于认证机构(CAS)的生态系统。负责发行和维护SSL证书的PKIS池,称为Web PKI,增长了非常大而复杂。这里,每个CA是单点故障,导致攻击表面,其尺寸几乎不可评估。本文涉及问题,如果可以减少攻击表面以最大限度地减少依赖恶意证书的风险。特别是,我们考虑该集合CAS的个性化。我们提出了一种称为rootopia的工具,其允许单独评估对用户相关的Web PKI的各个部分。我们对22个互联网用户的浏览器历史的分析显示,PKI的主要部分与单个用户完全无关。在每个用户级别上,攻击表面可以减少超过90%,这表明了该组可信CAS的个体化的潜力。此外,所有相关的CAS都居住在一小组国家内。我们的调查结果证实,我们不必要地信任大量的CA,从而使自己暴露于不必要的风险。随后,我们概述了我们实现可能的安全收益的方法。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号