【24h】

Exploring the Security of Certificate Transparency in the Wild

机译:探索野外证书透明度的安全性

获取原文

摘要

Certificate Transparency (CT) is proposed to detect fraudulent certificates and improve the accountability of CAs. CT as an open auditing and monitoring system is based on the idea that all CA-issued certificates are logged in a publicly accessible log server, and that CT-compliant browsers only accept publicly recorded certificates. The purpose of CT is to make all TLS server certificates issued by the CA publicly visible; once a fraudulent certificate is publicly published, it can be discovered by the domain name owner. In practice, the CT can achieve its intended purpose only when the three components (i.e., log server, monitor, and auditor) of the CT cooperate and work correctly and effectively. Compared with traditional PKI systems, the CT framework does not rely on a single trusted party, but as a distributed system that distributes trust guarantees to many CAs, log servers, auditors, and monitors. In this paper, we study the interaction among log servers, monitors, auditors, CAs, domain owners (or websites), browsers, and other components in practice, and then analyze the security impact of each component on the CT. We explore the security of CT framework in practice from multiple perspectives, and find that each component has many security vulnerabilities. Thus, the attackers might first exploit the vulnerability to disable the CT and then launch an attack using fraudulent certificates. The overall security guarantees of CT are jeopardized due to the weak protections of any components.
机译:建议证书透明度(CT)检测欺诈性证书并提高CAS的问责制。 CT作为开放审计和监控系统是基于概念,即所有CA发出的证书都在公开访问的日志服务器中登录,并且符合CT的浏览器仅接受公开录制的证书。 CT的目的是使CA公开可见的所有TLS服务器证书;一旦欺诈性证书公开发布,可以通过域名所有者发现它。在实践中,CT只有在CT的三个组件(即,Log Server,Monitor和审核员)正确有效地协作和工作时才才能实现其预期目的。与传统的PKI系统相比,CT框架不依赖于单个可信方,而是作为分布式系统,该系统将信托保证分配给许多CAS,日志服务器,审计师和监视器。在本文中,我们在实践中研究日志服务器,监视器,审计员,CAS,域所有者(或网站),浏览器和其他组件之间的交互,然后分析CT上每个组件的安全影响。从多个角度来看,我们在实践中探讨CT框架的安全性,并发现每个组件具有许多安全漏洞。因此,攻击者可能首先利用漏洞禁用CT,然后使用欺诈性证书启动攻击。由于任何组件的保护弱,CT的整体安全保障受到损害。

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号