Hammurabi: A Framework for Pluggable, Logic-Based X.509 Certificate Validation Policies

Hammurabi: A Framework for Pluggable, Logic-Based X.509 Certificate Validation Policies
复制标题

Hammurabi:可插入、基于逻辑的 X.509 证书验证策略框架

DOI:
10.1145/3548606.3560594
复制
发表时间:
2022
期刊:
Proceedings of the ACM Conference on Computer and Communications Security (CCS
影响因子:
--
通讯作者:
Maggs, Bruce M.
Maggs, Bruce M.
中科院分区:
--
文献类型:
--
作者:
Larisch, James;Aqeel, Waqar;Lum, Michael;Goldschlag, Yaelle;Kannan, Leah;Torshizi, Kasra;Wang, Yujie;Chung, Taejoong;Levin, Dave;Maggs, Bruce M.

文献摘要

参考文献

被引文献

相似文献

本文提出用逻辑编程语言将X.509证书验证策略从机制中解脱出来。用逻辑编程语言表达验证策略有多种好处。首先,与当前将策略和机制交织在C或C++实现中的做法相比,策略和机制可以更独立地编写、扩充和分析。一旦写入,就可以轻松地共享和修改这些策略,以便在不同的TLS客户端中使用。此外,逻辑编程允许我们确定何时客户端的策略不同,并使用归罪的能力来自动生成有趣的证书,例如,一个浏览器可以接受而另一个浏览器不能接受的证书。我们提出了一个新的框架HamMurabi来表示验证策略,并证明了我们可以在这个框架中表达Google Chrome和Mozilla Firefox Web浏览器的复杂策略。我们通过将HamMurabi策略所做的验证决定与浏览器自己对从证书透明度日志派生的1000多万个证书链以及100K合成链所做的验证决定进行比较,来确认这些策略的保真度。我们还使用推算发现了两个浏览器策略之间的九个验证差异。最后,我们用不到100行的代码演示了将HamMurabi集成到Firefox和Go语言中的可行性。
This paper proposes using a logic programming language to disentangle X.509 certificate validation policy from mechanism. Expressing validation policies in a logic programming language provides multiple benefits. First, policy and mechanism can be more independently written, augmented, and analyzed compared to the current practice of interweaving them within a C or C++ implementation. Once written, these policies can be easily shared and modified for use in different TLS clients. Further, logic programming allows us to determine when clients differ in their policies and use the power of imputation to automatically generate interesting certificates, e.g., a certificate that will be accepted by one browser but not by another.We present a new framework called Hammurabi for expressing validation policies, and we demonstrate that we can express the complex policies of the Google Chrome and Mozilla Firefox web browsers in this framework. We confirm the fidelity of the Hammurabi policies by comparing the validation decisions they make with those made by the browsers themselves on over ten million certificate chains derived from Certificate Transparency logs, as well as 100K synthetic chains. We also use imputation to discover nine validation differences between the two browsers' policies. Finally, we demonstrate the feasibility of integrating Hammurabi into Firefox and the Go language in less than 100 lines of code each.
EverParse:经过验证的安全零拷贝解析器,用于经过身份验证的消息格式
DOI: --
发表时间: 2019
期刊: USENIX Security Symposium
影响因子: --
作者:
A. Shukla;Rajeev Srivastava
通讯作者: Rajeev Srivastava
与政策无关的程序的分面执行
DOI: 10.1145/2465106.2465121
发表时间: 2013
期刊: ACM SIGOPS Oper. Syst. Rev.
影响因子: --
作者:
Thomas H. Austin;Jean Yang;C. Flanagan;Armando Solar
通讯作者: Armando Solar
Guardat:在存储层执行数据策略
DOI: --
发表时间: 2015
期刊: European Conference on Computer Systems
影响因子: --
作者:
Anjo Vahldiek;Eslam Elnikety;Aastha Mehta;D. Garg;P. Druschel;R. Rodrigues;J. Gehrke;Ansley Post
通讯作者: Ansley Post
Thoth:数据检索系统中的全面策略合规性
DOI: --
发表时间: 2016
期刊: USENIX Security Symposium
影响因子: --
作者:
Eslam Elnikety;Aastha Mehta;Anjo Vahldiek;D. Garg;P. Druschel
通讯作者: P. Druschel
SWI-Prolog 的有限域约束求解器
DOI: --
发表时间: 2012
期刊: Fuji International Symposium on Functional and Logic Programming
影响因子: --
作者:
Markus Triska
通讯作者: Markus Triska