跳到主要导航 跳到搜索 跳到主要内容

The Invisible Side of Certificate Transparency: Exploring the Reliability of Monitors in the Wild

  • Bingyu Li
  • , Jingqiang Lin*
  • , Fengjun Li
  • , Qiongxiao Wang
  • , Wei Wang
  • , Qi Li
  • , Guangshen Cheng
  • , Jiwu Jing
  • , Congli Wang
  • *此作品的通讯作者
  • University of Science and Technology of China
  • University of Kansas
  • CAS - Institute of Information Engineering
  • Tsinghua University
  • University of Chinese Academy of Sciences
  • China Telecommunications

科研成果: 期刊稿件文章同行评审

摘要

To detect fraudulent TLS server certificates and improve the accountability of certification authorities (CAs), certificate transparency (CT) is proposed to record certificates in publicly-visible logs, from which the monitors fetch all certificates and watch for suspicious ones. However, if the monitors, either domain owners themselves or third-party services, fail to return a complete set of certificates issued for a domain of interest, potentially fraudulent certificates may not be detected and then the CT framework becomes less reliable. This paper presents the first systematic study on CT monitors. We analyze the data in 88 public logs and the services of 5 active third-party monitors regarding 3,000,431 certificates of 6,000 selected Alexa Top-1M websites. We find that although CT allows ordinary domain owners to act as monitors, it is impractical for them to perform reliable processing by themselves, due to the rapidly increasing volume of certificates in public logs (e.g., on average about 5 million records or 28.29 GB daily for the minimal set of logs that need to be monitored in 2018, or more than 7 million records per day in 2020, according to the Chrome CT policy). Moreover, our study discloses that (a) none of the third-party monitors guarantees to return the complete set of certificates for a domain, and (b) for some domains, even the union of the certificates returned by the five third-party monitors can probably be incomplete. As a result, the certificates accepted by CT-enabled browsers are not actually visible to the claimed domain owners, even when CT is adopted with well-functioning logs. The risk of invisible fraudulent certificates in public logs raises doubts on the reliability of CT in practice.

源语言英语
页(从-至)749-765
页数17
期刊IEEE/ACM Transactions on Networking
30
2
DOI
出版状态已出版 - 1 4月 2022

学术指纹

探究 'The Invisible Side of Certificate Transparency: Exploring the Reliability of Monitors in the Wild' 的科研主题。它们共同构成独一无二的学术指纹。

引用此