详细信息
On the Detection of Fake Certificates via Attribute Correlation ( SCI-EXPANDED收录)
文献类型:期刊文献
英文题名:On the Detection of Fake Certificates via Attribute Correlation
作者:Gu, Xiaojing[1];Gu, Xingsheng[1]
机构:[1]E China Univ Sci & Technol, Key Lab Adv Control & Optimizat Chem Proc, Minist Educ, Shanghai 200237, Peoples R China
年份:2015
卷号:17
期号:6
起止页码:3806
外文期刊名:ENTROPY
收录:;WOS:【SCI-EXPANDED(收录号:WOS:000357803000017)】;
基金:The work was supported by the National Natural Science Foundation of China under Grant No. 61205017 and the Fundamental Research Funds for the Central Universities.
语种:英文
外文关键词:certification; man-in-the-middle attacks; attribute correlation
摘要:Transport Layer Security (TLS) and its predecessor, SSL, are important cryptographic protocol suites on the Internet. They both implement public key certificates and rely on a group of trusted certificate authorities (i.e., CAs) for peer authentication. Unfortunately, the most recent research reveals that, if any one of the pre-trusted CAs is compromised, fake certificates can be issued to intercept the corresponding SSL/TLS connections. This security vulnerability leads to catastrophic impacts on SSL/TLS-based HTTPS, which is the underlying protocol to provide secure web services for e-commerce, e-mails, etc. To address this problem, we design an attribute dependency-based detection mechanism, called SSLight. SSLight can expose fake certificates by checking whether the certificates contain some attribute dependencies rarely occurring in legitimate samples. We conduct extensive experiments to evaluate SSLight and successfully confirm that SSLight can detect the vast majority of fake certificates issued from any trusted CAs if they are compromised. As a real-world example, we also implement SSLight as a Firefox add-on and examine its capability of exposing existent fake certificates from DigiNotar and Comodo, both of which have made a giant impact around the world.
参考文献:
正在载入数据...
