NICRSep 21, 2018

The Rise of Certificate Transparency and Its Implications on the Internet Ecosystem

arXiv:1809.08325v183 citations
Originality Incremental advance
AI Analysis

This work addresses security and privacy risks in the internet ecosystem due to CT deployment, with incremental contributions in threat analysis.

The paper analyzes the growth of Certificate Transparency (CT) and its security and privacy implications, finding exponential growth in CT logs and that 33% of established connections now support CT, while also demonstrating that CT data is used for scanning campaigns within minutes of certificate issuance.

In this paper, we analyze the evolution of Certificate Transparency (CT) over time and explore the implications of exposing certificate DNS names from the perspective of security and privacy. We find that certificates in CT logs have seen exponential growth. Website support for CT has also constantly increased, with now 33% of established connections supporting CT. With the increasing deployment of CT, there are also concerns of information leakage due to all certificates being visible in CT logs. To understand this threat, we introduce a CT honeypot and show that data from CT logs is being used to identify targets for scanning campaigns only minutes after certificate issuance. We present and evaluate a methodology to learn and validate new subdomains from the vast number of domains extracted from CT logged certificates.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes