Certificate Transparency Revisited: The Public Inspections on Third-party Monitors
Aozhuo Sun, Jingqiang Lin, Wei Wang, Zeyan Liu, Bingyu Li, Shushang Wen, Qiongxiao Wang, Fengjun Li
摘要
The certificate transparency (CT) framework has been deployed to improve the accountability of the TLS certificate ecosystem. However, the current implementation of CT does not enforce or guarantee the correct behavior of third-party monitors, which are essential components of the CT framework, and raises security and reliability concerns. For example, recent studies [32], [33] reported that 5 popular third-party CT monitors cannot always return the complete set of certificates inquired by users, which fundamentally impairs the protection that CT aims to offer. This work revisits the CT design and proposes an additional component of the CT framework, CT watchers. A watcher acts as an inspector of third-party CT monitors to detect any misbehavior by inspecting the certificate search services of a third-party monitor and detecting any inconsistent results returned by multiple monitors. It also semi-automatically analyzes potential causes of the inconsistency, e.g., a monitor's misconfiguration, implementation flaws, etc. We implemented a prototype of the CT watcher and conducted a 52-day trial operation and several confirmation experiments involving 8.26M unique certificates of about 6,000 domains. From the results returned by 6 active thirdparty monitors in the wild, the prototype detected 14 potential design or implementation issues of these monitors, demonstrating its effectiveness in public inspections on third-party monitors and the potential to improve the overall reliability of CT. We revisit the CT framework design and propose a new component, called watchers, to inspect third-party monitor services. Similar to CT auditors that are tasked with detecting misbehavior on the logs, watchers are expected to detect misbehavior on third-party monitors, including faulty services and malicious actions. The watchers enable public inspections on third-party monitors and their certificate search services,
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper9
- Tracking Certificate Misissuance in the WildDeepak Kumar, Zhengping Wang, Matthew Hyder, Joseph Dickinson 等S&P 2018 · 被引用 86 次
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford 等USENIX Security 2018 · 被引用 83 次
- Merkle2: A Low-Latency Transparency Log SystemYuncong Hu, Kian Hooshmand, Harika Kalidhindi, Seung Jin Yang 等S&P 2021 · 被引用 51 次
- Certificate Transparency in the Wild: Exploring the Reliability of MonitorsBingyu Li, Jingqiang Lin, Fengjun Li, Qiongxiao Wang 等CCS 2019 · 被引用 45 次
- Does Certificate Transparency Break the Web? Measuring Adoption and Error RateEmily Stark, Ryan Sleevi, Rijad Muminovic, Devon O'Brien 等S&P 2019 · 被引用 44 次
相关 Paper
- Accountability in Certificate Transparency and VariantsTimo Treitz, Robert KünnemannCCS 2026
- CTng: Secure Certificate and Revocation TransparencyJie Kong, James Damon, Hemi Leibowitz, Ewa Syta 等NDSS 2026 · 被引用 5 次
- Uninvited Guests: Analyzing the Identity and Behavior of Certificate Transparency BotsBrian Kondracki, Johnny So, Nick NikiforakisUSENIX Security 2022
- IKP: Turning a PKI Around with Decentralized Automated IncentivesStephanos Matsumoto, Raphael M. ReischukS&P 2017 · 被引用 168 次
- SBDT: Search-Based Differential Testing of Certificate Parsers in SSL/TLS ImplementationsChu Chen, Pinghong Ren, Zhenhua Duan, Cong Tian 等ISSTA 2023 · 被引用 13 次
