Hammurabi: A Framework for Pluggable, Logic-Based X.509 Certificate Validation Policies
Hammurabi: A Framework for Pluggable, Logic-Based X.509 Certificate Validation Policies
复制标题
Hammurabi:可插入、基于逻辑的 X.509 证书验证策略框架
DOI:
10.1145/3548606.3560594
复制
发表时间:
2022
期刊:
影响因子:
--
通讯作者:
Maggs, Bruce M.
中科院分区:
文献类型:
--
作者:
Larisch, James;Aqeel, Waqar;Lum, Michael;Goldschlag, Yaelle;Kannan, Leah;Torshizi, Kasra;Wang, Yujie;Chung, Taejoong;Levin, Dave;Maggs, Bruce M.
This paper proposes using a logic programming language to disentangle X.509 certificate validation policy from mechanism. Expressing validation policies in a logic programming language provides multiple benefits. First, policy and mechanism can be more independently written, augmented, and analyzed compared to the current practice of interweaving them within a C or C++ implementation. Once written, these policies can be easily shared and modified for use in different TLS clients. Further, logic programming allows us to determine when clients differ in their policies and use the power of imputation to automatically generate interesting certificates, e.g., a certificate that will be accepted by one browser but not by another.We present a new framework called Hammurabi for expressing validation policies, and we demonstrate that we can express the complex policies of the Google Chrome and Mozilla Firefox web browsers in this framework. We confirm the fidelity of the Hammurabi policies by comparing the validation decisions they make with those made by the browsers themselves on over ten million certificate chains derived from Certificate Transparency logs, as well as 100K synthetic chains. We also use imputation to discover nine validation differences between the two browsers' policies. Finally, we demonstrate the feasibility of integrating Hammurabi into Firefox and the Go language in less than 100 lines of code each.
登录
查看更多内容
DOI:
--
发表时间:
2019
期刊:
USENIX Security Symposium
影响因子:
--
作者:
A. Shukla;Rajeev Srivastava
通讯作者:
Rajeev Srivastava
DOI:
10.1145/2465106.2465121
发表时间:
2013
期刊:
ACM SIGOPS Oper. Syst. Rev.
影响因子:
--
作者:
Thomas H. Austin;Jean Yang;C. Flanagan;Armando Solar
通讯作者:
Armando Solar
DOI:
--
发表时间:
2015
期刊:
European Conference on Computer Systems
影响因子:
--
作者:
Anjo Vahldiek;Eslam Elnikety;Aastha Mehta;D. Garg;P. Druschel;R. Rodrigues;J. Gehrke;Ansley Post
通讯作者:
Ansley Post
DOI:
--
发表时间:
2016
期刊:
USENIX Security Symposium
影响因子:
--
作者:
Eslam Elnikety;Aastha Mehta;Anjo Vahldiek;D. Garg;P. Druschel
通讯作者:
P. Druschel
DOI:
--
发表时间:
2012
期刊:
Fuji International Symposium on Functional and Logic Programming
影响因子:
--
作者:
Markus Triska
通讯作者:
Markus Triska