首页> 外文期刊>Journal of computer security >Systematic parsing of X.509: Eradicating security issues with a parse tree
【24h】

Systematic parsing of X.509: Eradicating security issues with a parse tree

机译:X.509的系统分析:使用分析树消除安全问题

获取原文
获取原文并翻译 | 示例

摘要

X.509 certificate parsing and validation is a critical task which has shown consistent lack of effectiveness, with practical attacks being reported with a steady rate during the last 10 years. In this work we analyze the X.509 standard and provide a grammar description of it amenable to the automated generation of a parser with strong termination guarantees, providing unambiguous input parsing. We report the results of analyzing a 11M X.509 certificate dump of the HTTPS servers running on the entire IPv4 space, showing that 21.5% of the certificates in use are syntactically invalid. We compare the results of our parsing against 7 widely used TLS libraries showing that 631k to 1,156k syntactically incorrect certificates are deemed valid by them (5.7%–10.5%), including instances with security critical mis-parsings. We prove the criticality of such mis-parsing exploiting one of the syntactic flaws found in existing certificates to perform an impersonation attack.
机译:X.509证书的解析和验证是一项关键任务,已显示出始终缺乏有效性,在过去的10年中,实用攻击的报告率一直稳定。在这项工作中,我们分析X.509标准,并对其进行语法描述,以使其能够自动生成具有强大终止保证的解析器,从而提供明确的输入解析。我们报告了在整个IPv4空间上运行的HTTPS服务器的11M X.509证书转储的分析结果,表明使用的证书中有21.5%在语法上无效。我们将解析结果与7个广泛使用的TLS库进行了比较,结果显示它们认为631k到1,156k的语法错误证书是有效的(5.7%–10.5%),包括具有严重安全性错误解析的实例。我们证明了利用现有证书中发现的一种语法缺陷进行模拟攻击的这种错误解析的重要性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号