USENIX Security2018Top-tier venue
The Broken Shield: Measuring Revocation Effectiveness in the Windows Code-Signing PKI
Doowon Kim, Bum Jun Kwon, Kristián Kozák, Christopher Gates, Tudor Dumitras
Abstract
Recent measurement studies have highlighted security threats against the code-signing public key infrastructure (PKI), such as certificates that had been compromised or issued directly to the malware authors. The primary mechanism for mitigating these threats is to revoke the abusive certificates. However, the distributed yet closed nature of the code signing PKI makes it difficult to evaluate the effectiveness of revocations in this ecosystem. In consequence, the magnitude of signed malware threat is not fully understood. In this paper, we collect seven datasets, including the largest corpus of code-signing certificates, and we combine them to analyze the revocation process from end to end. Effective revocations rely on three roles: (1) discovering the abusive certificates, (2) revoking the certificates effectively, and (3) disseminating the revocation information for clients. We assess the challenge for discovering compromised certificates and the subsequent revocation delays. We show that erroneously setting revocation dates causes signed malware to remain valid even after the certificate has been revoked. We also report failures in disseminating the revocations, leading clients to continue trusting the revoked certificates. Role Finding Implication Discovery of Potentially Compromised Certificates The mark-recapture estimation for the number of compromised certificates suggests that even a large AV vendor can only see about 36.5% of the population. There might be malware with compromised certificates that remain a threat for a long time without being detected. CAs took on average 171.4 days to revoke the compromised certificates after the malware signed with the certificates appeared in the wild. Compromised certificates are not discovered and revoked for a long time. Setting Revocation Date CAs erroneously set effective revocation dates for 62 certificates, causing 402 signed malware to remain valid. Wrong effective revocation date setting results in the survival of signed malware although its certificates is revoked. Dissemination of Revocation Information 788 certificates contain neither CRLs nor OCSP points. Clients have no way to check the revocation status of the certificates. 13 CRLs and 15 OCSP servers had reachability issues. OCSP servers responded with unknown or unauthorized messages. 19 certificates have inconsistent responses from CRLs and OCSP; they are valid from OCSP but are revoked in CRLs. CAs improperly maintain their CRLs and OCSP servers. 278 revoked certificates were added and then later removed from 18 CRLs. Errors in the revocation process are made, and later retracted. CAs misunderstood the code signing PKI and removed expired certificates from CRLs.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 342bb740-a1e7-4a3f-bce5-a36569b5477bCited by top-tier papers5
- C3PO: Large-Scale Study Of Covert Monitoring of C&C Servers via Over-Permissioned Protocol InfiltrationJonathan Fuller, Ranjita Pai Kasturi, Amit Kumar Sikder, Haichuan Xu et al.CCS 2021 · 6 citations
- Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century's Worth of SquabblesBoladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Alberto Dainotti et al.NDSS 2026 · 1 citation
- Measuring and Modeling the Label Dynamics of Online Anti-Malware EnginesShuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin et al.USENIX Security 2020
- Understanding the Status and Strategies of the Code Signing Abuse EcosystemHanqing Zhao, Yiming Zhang, Lingyun Ying, Mingming Zhang et al.NDSS 2026
- Enhanced Web Application Security Through Proactive Dead Drop Resolver RemediationJonathan Fuller, Mingxuan Yao, Saumya Agarwal, Srimanta Barua et al.CCS 2025
Builds on4
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin et al.CCS 2016 · 89 citations
- Tracking Certificate Misissuance in the WildDeepak Kumar, Zhengping Wang, Matthew Hyder, Joseph Dickinson et al.S&P 2018 · 86 citations
- Certified Malware: Measuring Breaches of Trust in the Windows Code-Signing PKIDoowon Kim, Bum Jun Kwon, Tudor DumitrasCCS 2017 · 64 citations
- Catching Worms, Trojan Horses and PUPs: Unsupervised Detection of Silent Delivery CampaignsBum Jun Kwon, Virinchi Srinivas, Amol Deshpande, Tudor DumitrasNDSS 2017 · 30 citations
Related papers
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford et al.USENIX Security 2018 · 83 citations
- Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI EcosystemYiming Zhang, Baojun Liu, Chaoyi Lu, Zhou Li et al.CCS 2021 · 16 citations
- S/MINE: Collecting and Analyzing S/MIME Certificates at ScaleGurur Öndarö, Jonas Kaspereit, Samson Umezulike, Christoph Saatjohann et al.USENIX Security 2025
- The Boon and Bane of Cross-Signing: Shedding Light on a Common Practice in Public Key InfrastructuresJens Hiller, Johanna Amann, Oliver HohlfeldCCS 2020 · 4 citations
- Indicator of Benignity: An Industry View of False Positive in Malicious Domain Detection and its MitigationDaiping Liu, Danyu Sun, Zhenhua Chen, Shu Wang et al.NDSS 2026
