VTechWorks staff will be away for the Independence Day holiday from July 4-7. We will respond to email inquiries on Monday, July 8. Thank you for your patience.
 

Exploring the Evolution of the TLS Certificate Ecosystem

dc.contributor.authorFarhan, Syed Muhammaden
dc.contributor.committeechairChung, Taejoong Tijayen
dc.contributor.committeememberGulzar, Muhammad Alien
dc.contributor.committeememberViswanath, Bimalen
dc.contributor.departmentComputer Scienceen
dc.date.accessioned2022-06-02T08:01:04Zen
dc.date.available2022-06-02T08:01:04Zen
dc.date.issued2022-06-01en
dc.description.abstractA vast majority of popular communication protocols for the internet employ the use of TLS (Transport Layer Security) to secure communication. As a result, there have been numerous efforts including the introduction of Certificate Transparency logs and Free Automated CAs to improve the SSL certificate ecosystem. Our work highlights the effectiveness of these efforts using the Certificate Transparency dataset as well as certificates collected via full IPv4 scans. We show that a large proportion of invalid certificates still exists and outline reasons why these certificates are invalid and where they are hosted. Moreover, we show that the incorrect use of template certificates has led to incorrect SCTs being embedded in the certificates. Taken together, our results emphasize continued involvement for the research community to improve the web's PKI ecosystem.en
dc.description.abstractgeneralSecurity and Privacy for communication over the internet is increasingly important. TLS (Transport Layer Security) is the most popular protocol used to secure communications over the internet today. This work explores how this protocol has evolved over the past 9 years and how effective the measures undertaken by the community have been to improve the adherence to best practices in the wild. TLS employs the use of certificates to initialize secure communication and make sure the other party is indeed who they say they are. We show that while security has improved over the years, a majority of certificates are invalid and outline reasons why. We also observe the growth of Certificate Transparency logs and show how the use of template certificates cause unexpected issues. Taken together, our results emphasize a continued involvement for the research community to improve the TLS certificate ecosystem.en
dc.description.degreeMaster of Scienceen
dc.format.mediumETDen
dc.identifier.othervt_gsexam:34689en
dc.identifier.urihttp://hdl.handle.net/10919/110403en
dc.language.isoenen
dc.publisherVirginia Techen
dc.rightsIn Copyrighten
dc.rights.urihttp://rightsstatements.org/vocab/InC/1.0/en
dc.subjectSecurityen
dc.subjectTLSen
dc.subjectCertificatesen
dc.subjectNetwork Securityen
dc.subjectCryptographyen
dc.subjectPublic Key Cryptographyen
dc.subjectWeb Security Protocolen
dc.subjectMeasurementen
dc.titleExploring the Evolution of the TLS Certificate Ecosystemen
dc.typeThesisen
thesis.degree.disciplineComputer Science and Applicationsen
thesis.degree.grantorVirginia Polytechnic Institute and State Universityen
thesis.degree.levelmastersen
thesis.degree.nameMaster of Scienceen

Files

Original bundle
Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Farhan_S_T_2022.pdf
Size:
1.19 MB
Format:
Adobe Portable Document Format

Collections