首页> 外文会议>IEEE Symposium on Security and Privacy >Does Certificate Transparency Break the Web? Measuring Adoption and Error Rate
【24h】

Does Certificate Transparency Break the Web? Measuring Adoption and Error Rate

机译:证书透明度会破坏网络吗?衡量采用率和错误率

获取原文

摘要

Certificate Transparency (CT) is an emerging system for enabling the rapid discovery of malicious or misissued certificates. Initially standardized in 2013, CT is now finally beginning to see widespread support. Although CT provides desirable security benefits, web browsers cannot begin requiring all websites to support CT at once, due to the risk of breaking large numbers of websites. We discuss challenges for deployment, analyze the adoption of CT on the web, and measure the error rates experienced by users of the Google Chrome web browser. We find that CT has so far been widely adopted with minimal breakage and warnings. Security researchers often struggle with the tradeoff between security and user frustration: rolling out new security requirements often causes breakage. We view CT as a case study for deploying ecosystem-wide change while trying to minimize end user impact. We discuss the design properties of CT that made its success possible, as well as draw lessons from its risks and pitfalls that could be avoided in future large-scale security deployments.
机译:证书透明性(CT)是一个新兴的系统,用于快速发现恶意或发行错误的证书。 CT最初于2013年标准化,现在终于开始获得广泛支持。尽管CT提供了理想的安全性好处,但是由于存在破坏大量网站的风险,Web浏览器无法开始要求所有网站同时支持CT。我们讨论了部署方面的挑战,分析了网络上CT的采用情况,并评估了Google Chrome浏览器网络浏览器用户遇到的错误率。我们发现,迄今为止,CT已被广泛采用,并且几乎没有破损和警告。安全研究人员经常在安全与用户沮丧之间进行权衡:推出新的安全要求通常会导致安全漏洞。我们将CT视为案例研究,旨在部署生态系统范围的变更,同时力求最大程度地减少最终用户的影响。我们将讨论CT的设计特性,以使其成功成为可能,并从其风险和陷阱中吸取教训,而这些风险和陷阱在将来的大规模安全部署中可以避免。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号