Detection of Rogue Certificates from Trusted Certificate Authorities Using Deep Neural Networks

Detection of Rogue Certificates from Trusted Certificate Authorities Using Deep Neural Networks
复制标题

使用深度神经网络检测来自受信任证书颁发机构的恶意证书

DOI:
--
复制
发表时间:
2016
影响因子:
2.3
通讯作者:
L. Camp
L. Camp
中科院分区:
计算机科学4区
文献类型:
--
作者:
Zheng Dong;K. Kane;L. Camp

文献摘要

被引文献

相似文献

流氓证书是由合法证书颁发机构(CA)颁发的有效证书,但不可信;但却得到了浏览器和用户的信任。对于当前的公钥基础设施,在颁发非法证书和检测到非法证书之间存在漏洞窗口。在检测和撤销之前,来自最近泄露的流氓证书已被信任长达数周。先前关闭此漏洞窗口的建议需要对基础设施、互联网协议或最终用户体验进行更改。我们提出了一种检测来自可信ca的流氓证书的方法,该方法是从大量及时的证书收集中开发的。该方法通过使用深度神经网络(DNN)构建机器学习模型来实现自动分类。尽管数据集中缺乏流氓实例,但DNN产生了一种分类方法,该方法在模拟和2014年7月印度CCA妥协中都得到了证明。我们报告了分类方法的细节,并说明了它是可重复的,例如通过爬行获得的数据集。我们描述了当前研究部署下的分类性能。
Rogue certificates are valid certificates issued by a legitimate certificate authority (CA) that are nonetheless untrustworthy; yet trusted by web browsers and users. With the current public key infrastructure, there exists a window of vulnerability between the time a rogue certificate is issued and when it is detected. Rogue certificates from recent compromises have been trusted for as long as weeks before detection and revocation. Previous proposals to close this window of vulnerability require changes in the infrastructure, Internet protocols, or end user experience. We present a method for detecting rogue certificates from trusted CAs developed from a large and timely collection of certificates. This method automates classification by building machine-learning models with Deep Neural Networks (DNN). Despite the scarcity of rogue instances in the dataset, DNN produced a classification method that is proven both in simulation and in the July 2014 compromise of the India CCA. We report the details of the classification method and illustrate that it is repeatable, such as with datasets obtained from crawling. We describe the classification performance under our current research deployment.