Talking with Familiar Strangers: An Empirical Study on HTTPS Context Confusion Attacks
Mingming Zhang, Xiaofeng Zheng, Kaiwen Shen, Ziqiao Kong, Chaoyi Lu, Yu Wang, Haixin Duan, Shuang Hao, Baojun Liu, Min Yang
摘要
HTTPS is principally designed for secure end-to-end communication, which adds confidentiality and integrity to sensitive data transmission. While several man-in-the-middle attacks (e.g., SSL Stripping) are available to break the secured connections, state-ofthe-art security policies (e.g., HSTS) have significantly increased the cost of successful attacks. However, the TLS certificates shared by multiple domains make HTTPS hijacking attacks possible again.
In this paper, we term the HTTPS MITM attacks based on the shared TLS certificates as HTTPS Context Confusion Attack (SCC Attack). Despite a known threat, it has not yet been studied thoroughly. We aim to fill this gap with an in-depth empirical assessment of SCC Attack. We find the attack can succeed even for servers that have deployed current best practice of security policies. By rerouting encrypted traffic to another flawed server that shares the TLS certificate, attackers can bypass the security practices, hijack the ongoing HTTPS connections, and subsequently launch additional attacks including phishing and payment hijacking. Particularly, vulnerable HTTP headers from a third-party server are exploitable for this attack, and it is possible to hijack an already-established secure connection.
Through tests on popular websites, we find vulnerable subdomains under 126 apex domains in Alexa top 500 sites, including large vendors like Alibaba, JD, and Microsoft. Meanwhile, through a large-scale measurement, we find that TLS certificate sharing is prominent, which uncovers the high potential of such attacks, and we summarize the security dependencies among different parties. For responsible disclosure, we have reported the issues to affected vendors and received positive feedback. Our study sheds light on an influential attack surface of the HTTPS ecosystem and calls for proper mitigation against MITM attacks.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Can I Take Your Subdomain? Exploring Same-Site Attacks in the Modern WebMarco Squarcina, Mauro Tempesta, Lorenzo Veronese, Stefano Calzavara 等USENIX Security 2021 · 被引用 30 次
- Investigating Influencer VPN Ads on YouTubeOmer Akgul, Richard Roberts, Moses Namara, Dave Levin 等S&P 2022 · 被引用 27 次
- ALPACA: Application Layer Protocol Confusion - Analyzing and Mitigating Cracks in TLS AuthenticationMarcus Brinkmann, Christian Dresen, Robert Merget, Damian Poddebniak 等USENIX Security 2021 · 被引用 20 次
- Your Space is My Zone: Demystifying the Security Risks of AI-Powered Applications on Pre-Trained Model HubsYacong Gu, Lingyun Ying, Zidong Zhang, Yingyuan Pu 等CCS 2026 · 被引用 1 次
- Investigating Package Related Security Threats in Software RegistriesYacong Gu, Lingyun Ying, Yingyuan Pu, Xiao Hu 等S&P 2023
它引用的顶会 Paper8
- All Things Considered: An Analysis of IoT Devices on Home NetworksDeepak Kumar, Kelly Shen, Benton Case, Deepali Garg 等USENIX Security 2019 · 被引用 189 次
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer 等USENIX Security 2017 · 被引用 177 次
- The Security Impact of HTTPS InterceptionZakir Durumeric, Zane Ma, Drew Springall, Richard Barnes 等NDSS 2017 · 被引用 161 次
- Killed by Proxy: Analyzing Client-end TLS Interception SoftwareXavier de Carné de Carnavalet, Mohammad MannanNDSS 2016 · 被引用 90 次
- The Cracked Cookie Jar: HTTP Cookie Hijacking and the Exposure of Private InformationSuphannee Sivakorn, Iasonas Polakis, Angelos D. KeromytisS&P 2016 · 被引用 86 次
相关 Paper
- Cross-Origin Web Attacks via HTTP/2 Server Push and Signed HTTP ExchangePinji Chen, Jianjun Chen, Mingming Zhang, Qi Wang 等NDSS 2025
- Postcards from the Post-HTTP World: Amplification of HTTPS Vulnerabilities in the Web EcosystemStefano Calzavara, Riccardo Focardi, Matús Nemec, Alvise Rabitti 等S&P 2019 · 被引用 24 次
- Off-Path TCP Exploits: PMTUD Breaks TCP Connection Isolation in IP Address Sharing ScenariosXuewei Feng, Zhaoxi Li, Qi Li, Ziqiang Wang 等CCS 2025
- Racing for TLS Certificate Validation: A Hijacker's Guide to the Android TLS GalaxySajjad Pourali, Xiufen Yu, Lianying Zhao, Mohammad Mannan 等USENIX Security 2024 · 被引用 7 次
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
