Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing Ecosystem

Security Analysis on Practices of Certificate Authorities in the HTTPS Phishing Ecosystem
复制标题

HTTPS钓鱼生态系统中证书颁发机构的做法安全分析

DOI:
10.1145/3433210.3453100
复制
发表时间:
2021
期刊:
The 2021 ACM Asia Conference on Computer and Communications Security (ASIA CCS'21
影响因子:
--
通讯作者:
Dumitras, Tudor
Dumitras, Tudor
中科院分区:
--
文献类型:
--
作者:
Kim, Doowon;Cho, Haehyun;Kwon, Yonghwi;Doupé, Adam;Son, Sooel;Ahn, Gail-Joon;Dumitras, Tudor

文献摘要

参考文献

被引文献

相似文献

尽管在学术界和工业界进行了广泛的努力,但网络钓鱼攻击仍造成了重大损害。最近,大量的网络钓鱼攻击转向采用HTTPS,利用证书颁发机构(CA)颁发的TLS证书,使攻击更加有效。在本文中,我们提出了一个全面的研究CA在HTTPS网络钓鱼生态系统中的安全实践。我们专注于CA,在以前的文献中研究不足的关键演员,以更好地了解CA的安全实践的重要性,并阻止激增的HTTPS网络钓鱼。特别是,我们首先介绍了HTTPS网络钓鱼攻击与传统HTTP网络钓鱼攻击相比的现状和有效性。然后,我们进行了一个实证实验的CA的安全实践方面的证书的发行和撤销。我们的研究结果突出了CA的预期安全实践与现实之间的严重冲突,引发了重大的安全问题。我们进一步验证了我们的研究结果使用纵向数据集的滥用证书用于真实的网络钓鱼攻击在野外。我们确认CA的安全问题在野外普遍存在,这些问题可能是最近HTTPS钓鱼攻击激增的主要原因之一。
Phishing attacks are causing substantial damage albeit extensive effort in academia and industry. Recently, a large volume of phishing attacks transit toward adopting HTTPS, leveraging TLS certificates issued from Certificate Authorities (CAs), to make the attacks more effective. In this paper, we present a comprehensive study on the security practices of CAs in the HTTPS phishing ecosystem. We focus on the CAs, critical actors under-studied in previous literature, to better understand the importance of the security practices of CAs and thwart the proliferating HTTPS phishing. In particular, we first present the current landscape and effectiveness of HTTPS phishing attacks comparing to traditional HTTP ones. Then, we conduct an empirical experiment on the CAs' security practices in terms of the issuance and revocation of the certificates. Our findings highlight serious conflicts between the expected security practices of CAs and reality, raising significant security concerns. We further validate our findings using a longitudinal dataset of abusive certificates used for real phishing attacks in the wild. We confirm that the security concerns of CAs prevail in the wild and these concerns can be one of the main contributors to the recent surge of HTTPS phishing attacks.
权衡背景和权衡:郊区成年人如何选择他们的在线安全态势
DOI: --
发表时间: 2017
期刊: Symposium On Usable Privacy and Security
影响因子: --
作者:
Scott Ruoti;T. Monson;Justin Wu;D. Zappala;K. Seamons
通讯作者: K. Seamons
DOI: 10.1145/3278532.3278569
发表时间: 2018-10
期刊: Proceedings of the Internet Measurement Conference 2018
影响因子: --
作者:
K. Tian;Steve T. K. Jan;Hang Hu;D. Yao;G. Wang
通讯作者: K. Tian;Steve T. K. Jan;Hang Hu;D. Yao;G. Wang
DOI: 10.17487/rfc8555
发表时间: 2019-03
期刊: RFC
影响因子: --
作者:
Richard L. Barnes;Jacob Hoffman-Andrews;D. McCarney;James Kasten
通讯作者: Richard L. Barnes;Jacob Hoffman-Andrews;D. McCarney;James Kasten
安全传输协议对网络钓鱼效率的影响
DOI: --
发表时间: 2019
期刊: CSET @ USENIX Security Symposium
影响因子: --
作者:
Zane Ma;J. Reynolds;Joseph Dickinson;Kaishen Wang;Taylor Judd;J. D. Barnes;Joshua Mason;Michael Bailey
通讯作者: Michael Bailey
DOI: 10.1145/1299015.1299016
发表时间: 2007-10
期刊: --
影响因子: --
作者:
T. Moore;R. Clayton
通讯作者: T. Moore;R. Clayton