When Certificate Transparency Is Too Transparent: Analyzing Information Leakage in HTTPS Domain Names

When Certificate Transparency Is Too Transparent: Analyzing Information Leakage in HTTPS Domain Names
复制标题

当证书透明度过于透明时:HTTPS域名信息泄露分析

DOI:
10.1145/3338498.3358655
复制
发表时间:
2019
期刊:
WPES
影响因子:
--
通讯作者:
Levin, Dave
Levin, Dave
中科院分区:
--
文献类型:
--
作者:
Roberts, Richard;Levin, Dave

文献摘要

参考文献

被引文献

相似文献

证书透明(Certificate Transparency, CT)是最近的一项倡议,它记录所有公开可用的证书,从而为证书颁发机构增加了一层额外的责任和可审计性。大多数用户和网站管理员都不知道,CT日志使所有证书中的所有数据公开且永久可用。虽然证书表面上是公开的(毕竟,它们的主要目的是传递实体的公钥),但管理员可能无意中包含了任何人都可以挖掘的信息。例如,CT日志中包含子域的证书,这自然有利于子域的枚举。本文的问题是:证书中是否包含其他更敏感的信息?我们在CT日志的证书域名中识别了几种类型的用户和企业信息。我们提供了获取用户名、用户名和电子邮件地址等信息的查询。我们还发现,CT日志可以泄露私有企业信息,例如业务关系、用户增长度量以及内部项目在公开发布之前的存在情况。我们报告了信息泄露的频率和跨多少个域的初步结果。最后,我们讨论了未来的工作领域和管理员可以采取的潜在对策。
Certificate Transparency (CT) is a recent initiative to log all publicly available certificates, thereby adding an extra layer of accountability and auditability to certificate authorities. Unbeknownst to most users and website administrators, CT logs make all data in all certificates available publicly and permanently. Although certificates are ostensibly intended to be public (after all, their main purpose is to convey an entity's public key), administrators may inadvertently include information that can be mined by anyone. For instance, CT logs contain certificates for subdomains, which naturally facilitates subdomain enumeration. This paper asks: is there other, more sensitive information included in certificates?We identify several types of user and enterprise information embedded within the domain names of certificates in CT logs. We provide queries for obtaining information such as users' names, usernames, and email addresses. We also find that CT logs can leak private enterprise information, such as business relationships, user growth measurements, and the existence of internal projects prior to their public announcements. We report initial results on how often and across how many domains information is leaked. Finally, we discuss areas of future work and potential countermeasures that administrators can take.
定义物联网安全目标:以价值为中心的思维方法
DOI: --
发表时间: 2016
期刊:
影响因子: --
作者:
G. Dhillon;Lemuria D. Carter;Javad Abed
通讯作者: Javad Abed
DOI: 10.4135/9781412952415.n271
发表时间: 2020
期刊: Federal Regulatory Guide
影响因子: --
作者:
Patrick DeGraba;Patrick Greenlee;Daniel P. O’Brien;Maureen K. Ohlhausen;Terrell McSweeny;Michael Vita;J. Pappalardo;Aileen J. Thompson;Stephanie Beckett;Geoffrey Greene;Matthew Mandelberg;Jim Mongoven
通讯作者: Patrick DeGraba;Patrick Greenlee;Daniel P. O’Brien;Maureen K. Ohlhausen;Terrell McSweeny;Michael Vita;J. Pappalardo;Aileen J. Thompson;Stephanie Beckett;Geoffrey Greene;Matthew Mandelberg;Jim Mongoven