The Broken Shield: Measuring Revocation Effectiveness in the Windows Code-Signing PKI
Doowon Kim, Bum Jun Kwon, Kristián Kozák, Christopher Gates, Tudor Dumitras
摘要
Recent measurement studies have highlighted security threats against the code-signing public key infrastructure (PKI), such as certificates that had been compromised or issued directly to the malware authors. The primary mechanism for mitigating these threats is to revoke the abusive certificates. However, the distributed yet closed nature of the code signing PKI makes it difficult to evaluate the effectiveness of revocations in this ecosystem. In consequence, the magnitude of signed malware threat is not fully understood. In this paper, we collect seven datasets, including the largest corpus of code-signing certificates, and we combine them to analyze the revocation process from end to end. Effective revocations rely on three roles: (1) discovering the abusive certificates, (2) revoking the certificates effectively, and (3) disseminating the revocation information for clients. We assess the challenge for discovering compromised certificates and the subsequent revocation delays. We show that erroneously setting revocation dates causes signed malware to remain valid even after the certificate has been revoked. We also report failures in disseminating the revocations, leading clients to continue trusting the revoked certificates. Role Finding Implication Discovery of Potentially Compromised Certificates The mark-recapture estimation for the number of compromised certificates suggests that even a large AV vendor can only see about 36.5% of the population. There might be malware with compromised certificates that remain a threat for a long time without being detected. CAs took on average 171.4 days to revoke the compromised certificates after the malware signed with the certificates appeared in the wild. Compromised certificates are not discovered and revoked for a long time. Setting Revocation Date CAs erroneously set effective revocation dates for 62 certificates, causing 402 signed malware to remain valid. Wrong effective revocation date setting results in the survival of signed malware although its certificates is revoked. Dissemination of Revocation Information 788 certificates contain neither CRLs nor OCSP points. Clients have no way to check the revocation status of the certificates. 13 CRLs and 15 OCSP servers had reachability issues. OCSP servers responded with unknown or unauthorized messages. 19 certificates have inconsistent responses from CRLs and OCSP; they are valid from OCSP but are revoked in CRLs. CAs improperly maintain their CRLs and OCSP servers. 278 revoked certificates were added and then later removed from 18 CRLs. Errors in the revocation process are made, and later retracted. CAs misunderstood the code signing PKI and removed expired certificates from CRLs.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- C3PO: Large-Scale Study Of Covert Monitoring of C&C Servers via Over-Permissioned Protocol InfiltrationJonathan Fuller, Ranjita Pai Kasturi, Amit Kumar Sikder, Haichuan Xu 等CCS 2021 · 被引用 6 次
- Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century's Worth of SquabblesBoladji Vinny Adjibi, Athanasios Avgetidis, Manos Antonakakis, Alberto Dainotti 等NDSS 2026 · 被引用 1 次
- Measuring and Modeling the Label Dynamics of Online Anti-Malware EnginesShuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin 等USENIX Security 2020
- Understanding the Status and Strategies of the Code Signing Abuse EcosystemHanqing Zhao, Yiming Zhang, Lingyun Ying, Mingming Zhang 等NDSS 2026
- Enhanced Web Application Security Through Proactive Dead Drop Resolver RemediationJonathan Fuller, Mingxuan Yao, Saumya Agarwal, Srimanta Barua 等CCS 2025
它引用的顶会 Paper4
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- Tracking Certificate Misissuance in the WildDeepak Kumar, Zhengping Wang, Matthew Hyder, Joseph Dickinson 等S&P 2018 · 被引用 86 次
- Certified Malware: Measuring Breaches of Trust in the Windows Code-Signing PKIDoowon Kim, Bum Jun Kwon, Tudor DumitrasCCS 2017 · 被引用 64 次
- Catching Worms, Trojan Horses and PUPs: Unsupervised Detection of Silent Delivery CampaignsBum Jun Kwon, Virinchi Srinivas, Amol Deshpande, Tudor DumitrasNDSS 2017 · 被引用 30 次
相关 Paper
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford 等USENIX Security 2018 · 被引用 83 次
- Rusted Anchors: A National Client-Side View of Hidden Root CAs in the Web PKI EcosystemYiming Zhang, Baojun Liu, Chaoyi Lu, Zhou Li 等CCS 2021 · 被引用 16 次
- S/MINE: Collecting and Analyzing S/MIME Certificates at ScaleGurur Öndarö, Jonas Kaspereit, Samson Umezulike, Christoph Saatjohann 等USENIX Security 2025
- The Boon and Bane of Cross-Signing: Shedding Light on a Common Practice in Public Key InfrastructuresJens Hiller, Johanna Amann, Oliver HohlfeldCCS 2020 · 被引用 4 次
- Indicator of Benignity: An Industry View of False Positive in Malicious Domain Detection and its MitigationDaiping Liu, Danyu Sun, Zhenhua Chen, Shu Wang 等NDSS 2026
