English
Related papers

Related papers: Do CAA, CT, and DANE Interlink in Certificate Depl…

200 papers

We present CAI Dataset, a fourteen-month corpus of cybersecurity LLM trajectories collected through the open-source CAI agent framework, built in response to PentestGPT's finding that expert operator trajectories, not base-model capability,…

Cryptography and Security · Computer Science 2026-05-28 Víctor Mayoral-Vilches

Traditionally, publicly available repositories of certificates offer the usual response to the problem of public key distribution. After issuing a public-key certificate a certification authority (CA) - in the frame of a particular…

Cryptography and Security · Computer Science 2019-10-21 Marius Marian , Diana Berbecaru

X.509 certificate parsing and validation is a critical task which has shown consistent lack of effectiveness, with practical attacks being reported with a steady rate during the last 10 years. In this work we analyze the X.509 standard and…

Cryptography and Security · Computer Science 2018-12-13 Alessandro Barenghi , Nicholas Mainardi , Gerardo Pelosi

X.509 certificates play a crucial role in establishing secure communication over the internet by enabling authentication and data integrity. Equipped with a rich feature set, the X.509 standard is defined by multiple, comprehensive ISO/IEC…

Cryptography and Security · Computer Science 2024-05-30 Stefan Tatschner , Sebastian N. Peters , Michael P. Heinl , Tobias Specht , Thomas Newe

Several encryption proposals for DNS have been presented since 2016, but their adoption was not comprehensively studied yet. This research measured the current adoption of DoH (DNS over HTTPS), DoT (DNS over TLS), and DoQ (DNS over QUIC)…

Cryptography and Security · Computer Science 2021-07-12 Sebastián García , Karel Hynek , Dmtrii Vekshin , Tomáš Čejka , Armin Wasicek

In conventional PKI, CAs are assumed to be fully trusted. However, in practice, CAs' absolute responsibility for providing trustworthiness caused major security and privacy issues. To prevent such issues, Google introduced the concept of…

Cryptography and Security · Computer Science 2018-10-02 Murat Yasin Kubilay , Mehmet Sabir Kiraz , Haci Ali Mantar

This paper presents a measurement study of information leakage and SSL vulnerabilities in popular Android apps. We perform static and dynamic analysis on 100 apps, downloaded at least 10M times, that request full network access. Our…

Cryptography and Security · Computer Science 2015-05-05 Lucky Onwuzurike , Emiliano De Cristofaro

Certificate transparency (CT) is an elegant mechanism designed to detect when a certificate authority (CA) has issued a certificate incorrectly. Many CAs now support CT and it is being actively deployed in browsers. However, a number of…

Cryptography and Security · Computer Science 2017-08-08 Saba Eskandarian , Eran Messeri , Joseph Bonneau , Dan Boneh

Mutual TLS (mTLS) provides strong, certificate-based authentication for both clients and servers, yet its adoption for user-facing websites remains rare. This paper presents a longitudinal study of mTLS usability, tracking 46 senior and…

Cryptography and Security · Computer Science 2026-05-01 Abubakar Sadiq Shittu , Clay Shubert , John Sadik , Scott Ruoti

The Domain Name System (DNS) plays a foundational role in Internet infrastructure, yet its core protocols remain vulnerable to compromise by quantum adversaries. As cryptographically relevant quantum computers become a realistic threat,…

Cryptography and Security · Computer Science 2025-06-26 Juyoul Lee , Sanzida Hoque , Abdullah Aydeger , Engin Zeydan

The domain name system (DNS) is one of the most important components of today's Internet, and is the standard naming convention between human-readable domain names and machine-routable IP addresses of Internet resources. However, due to the…

Networking and Internet Architecture · Computer Science 2020-06-30 Aminollah Khormali , Jeman Park , Hisham Alasmary , Afsah Anwar , David Mohaisen

When the global rollout of the DNS Security Extensions (DNSSEC) began in 2005, a first-of-its-kind trial started: The complexity of a core Internet protocol was magnified in favor of better security for the overall Internet. Thereby, the…

Cryptography and Security · Computer Science 2024-09-12 Eric Osterweil , Pouyan Fotouhi Tehrani , Thomas C. Schmidt , Matthias Wählisch

Due to increasing digitalization, formerly isolated industrial networks, e.g., for factory and process automation, move closer and closer to the Internet, mandating secure communication. However, securely setting up OPC UA, the prime…

Cryptography and Security · Computer Science 2020-10-27 Markus Dahlmanns , Johannes Lohmöller , Ina Berenice Fink , Jan Pennekamp , Klaus Wehrle , Martin Henze

Many of the benefits we derive from the Internet require trust in the authenticity of HTTPS connections. Unfortunately, the public key certification ecosystem that underwrites this trust has failed us on numerous occasions. Towards an…

Cryptography and Security · Computer Science 2018-01-04 Jan-Ole Malchow , Benjamin Güldenring , Volker Roth

Trusted Execution Environments (TEEs), such as Intel SGX and ARM TrustZone, provide isolated regions of CPU and memory for secure computation and are increasingly used to protect sensitive data and code across diverse application domains.…

Software Engineering · Computer Science 2026-01-21 Yuqing Niu , Jieke Shi , Ruidong Han , Ye Liu , Chengyan Ma , Yunbo Lyu , David Lo

TLS uses X.509 certificates for server authentication. A X.509 certificate is a complex document and various innocent errors may occur while creating/ using it. Also, many certificates belong to malicious websites and should be rejected by…

Cryptography and Security · Computer Science 2017-05-26 Sankalp Bagaria , R. Balaji , B. S. Bindhumadhava

DNS dynamic updates represent an inherently vulnerable mechanism deliberately granting the potential for any host to dynamically modify DNS zone files. Consequently, this feature exposes domains to various security risks such as domain…

Cryptography and Security · Computer Science 2024-06-06 Yevheniya Nosyk , Maciej Korczyński , Carlos H. Gañán , Michał Król , Qasim Lone , Andrzej Duda

The current Domain Name System (DNS) infrastructure faces critical vulnerabilities including poisoning attacks, censorship mechanisms, and centralized points of failure that compromise internet freedom and security. Recent incidents such as…

Cryptography and Security · Computer Science 2025-08-11 Guang Yang , Peter Trinh , Alma Nkemla , Amuru Serikyaku , Edward Tatchim , Osman Sharaf

The use of TLS proxies to intercept encrypted traffic is controversial since the same mechanism can be used for both benevolent purposes, such as protecting against malware, and for malicious purposes, such as identity theft or warrantless…

Cryptography and Security · Computer Science 2015-05-29 Mark O'Neill , Scott Ruoti , Kent Seamons , Daniel Zappala

Cloud-based services have become part of our day-to-day software solutions. The identity authentication process is considered to be the main gateway to these services. As such, these gates have become increasingly susceptible to aggressive…

Cryptography and Security · Computer Science 2017-11-27 Marwan Darwish , Abdelkader Ouda , Luiz Fernando Capretz