The rise of certificate transparency and its implications on the internet ecosystem

57Citations
Citations of this article
55Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In this paper, we analyze the evolution of Certificate Transparency (CT) over time and explore the implications of exposing certificate DNS names from the perspective of security and privacy. We find that certificates in CT logs have seen exponential growth. Website support for CT has also constantly increased, with now 33% of established connections supporting CT. With the increasing deployment of CT, there are also concerns of information leakage due to all certificates being visible in CT logs. To understand this threat, we introduce a CT honeypot and show that data from CT logs is being used to identify targets for scanning campaigns only minutes after certificate issuance. We present and evaluate a methodology to learn and validate new subdomains from the vast number of domains extracted from CT logged certificates.

Cite

CITATION STYLE

APA

Scheitle, Q., Gasser, O., Nolte, T., Amann, J., Brent, L., Carle, G., … Wählisch, M. (2018). The rise of certificate transparency and its implications on the internet ecosystem. In Proceedings of the ACM SIGCOMM Internet Measurement Conference, IMC (pp. 343–349). Association for Computing Machinery. https://doi.org/10.1145/3278532.3278562

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free