中文
相关论文

相关论文: Do CAA, CT, and DANE Interlink in Certificate Depl…

200 篇论文

"Distributed Identity" refers to the transition from centralized identity systems using Decentralized Identifiers (DID) and Verifiable Credentials (VC) for secure and privacy-preserving authentications. With distributed identity, control of…

密码学与安全 · 计算机科学 2025-01-17 Sina Ahmadi

DNS is one of the core building blocks of the Internet. In this paper, we investigate DNS resolution in a strict IPv6-only scenario and find that a substantial fraction of zones cannot be resolved. We point out, that the presence of an AAAA…

网络与互联网体系结构 · 计算机科学 2023-02-23 Florian Streibelt , Patrick Sattler , Franziska Lichtblau , Carlos H. Gañán , Anja Feldmann , Oliver Gasser , Tobias Fiebig

Third-party web tracking is a common, and broadly used technique on the Web. Almost every step of users' is tracked, analyzed, and later used in different use cases (e.g., online advertisement). Different defense mechanisms have emerged to…

密码学与安全 · 计算机科学 2022-02-11 Nurullah Demir , Daniel Theis , Tobias Urban , Norbert Pohlmann

Web-based chatbots provide website owners with the benefits of increased sales, immediate response to their customers, and insight into customer behaviour. While Web-based chatbots are getting popular, they have not received much scrutiny…

密码学与安全 · 计算机科学 2022-05-18 Nazar Waheed , Muhammad Ikram , Saad Sajid Hashmi , Xiangjian He , Priyadarsi Nanda

The adoption of security protocols such as Transport Layer Security (TLS) has significantly improved the state of traffic encryption and integrity protection on the Internet. Despite rigorous analysis, vulnerabilities continue to emerge,…

密码学与安全 · 计算机科学 2025-01-30 Mariam Moustafa , Mohit Sethi , Tuomas Aura

Software vulnerabilities continue to be the primary cause of cyberattacks. It is crucial to identify vulnerabilities in applications' source code before attackers gain access to them and exploit any vulnerability they may contain.…

软件工程 · 计算机科学 2026-05-26 Jorge Martins , David Dantas , Rafael Ramires , Bernardo Ferreira , Ibéria Medeiros

Auditing plays a pivotal role in the development of trustworthy AI. However, current research primarily focuses on creating auditable AI documentation, which is intended for regulators and experts rather than end-users affected by AI…

计算机与社会 · 计算机科学 2023-05-31 Nicolas Scharowski , Michaela Benk , Swen J. Kühne , Léane Wettstein , Florian Brühlmann

Since security was not among the original design goals of the Domain Name System (herein called Vanilla DNS), many secure DNS schemes have been proposed to enhance the security and privacy of the DNS resolution process. Some proposed…

密码学与安全 · 计算机科学 2026-04-20 Ali Sadeghi Jahromi , AbdelRahman Abdou , Paul C. van Oorschot

It is notoriously difficult to securely configure HTTPS, and poor server configurations have contributed to several attacks including the FREAK, Logjam, and POODLE attacks. In this work, we empirically evaluate the TLS security posture of…

密码学与安全 · 计算机科学 2021-11-02 Camelia Simoiu , Wilson Nguyen , Zakir Durumeric

Within a trust infrastructure, a private key is often used to digitally sign a transaction, which can be verified with an associated public key. Using PKI (Public Key Infrastructure), a trusted entity can produce a digital signature,…

密码学与安全 · 计算机科学 2023-10-11 Sam Grierson , William J Buchanan , Craig Thomson , Baraq Ghaleb , Leandros Maglaras , Chris Eckl

The ability to quickly revoke a compromised key is critical to the security of any public-key infrastructure. Regrettably, most traditional certificate revocation schemes suffer from latency, availability, or privacy problems. These…

密码学与安全 · 计算机科学 2020-09-15 Laurent Chuat , AbdelRahman Abdou , Ralf Sasse , Christoph Sprenger , David Basin , Adrian Perrig

Static analysis tools are widely used for vulnerability detection as they understand programs with complex behavior and millions of lines of code. Despite their popularity, static analysis tools are known to generate an excess of false…

软件工程 · 计算机科学 2021-02-17 Yunhui Zheng , Saurabh Pujar , Burn Lewis , Luca Buratti , Edward Epstein , Bo Yang , Jim Laredo , Alessandro Morari , Zhong Su

The current Domain Name System (DNS), as a core infrastructure of the internet, exhibits several shortcomings: its centralized architecture leads to censorship risks and single points of failure, making domain name resolution vulnerable to…

网络与互联网体系结构 · 计算机科学 2024-12-25 Guang Yang

The Domain Name System (DNS) does not provide query privacy. Query obfuscation schemes have been proposed to overcome this limitation, but, so far, they have not been evaluated in a realistic setting. In this paper we evaluate the security…

密码学与安全 · 计算机科学 2016-03-23 Dominik Herrmann , Max Maaß , Hannes Federrath

Privacy-aware processing of personal data on the web of services requires managing a number of issues arising both from the technical and the legal domain. Several approaches have been proposed to matching privacy requirements (on the…

密码学与安全 · 计算机科学 2015-04-16 Marco Anisetti , Claudio A. Ardagna , Michele Bezzi , Ernesto Damiani , Antonino Sabetta

TR-069 is a standard for the remote management of end-user devices by service providers. Despite being implemented in nearly a billion devices, almost no research has been published on the security and privacy aspects of TR-069. The first…

网络与互联网体系结构 · 计算机科学 2020-01-09 Maximilian Hils , Rainer Böhme

As of today, TLS is the most commonly used protocol to protect communication content. To provide good security, it is of central importance, that administrators know how to configure their services correctly. For this purpose, services…

人机交互 · 计算机科学 2018-09-25 Christian Tiefenau , Emanuel von Zezschwitz

The transition to post-quantum cryptography (PQC) presents significant challenges for certificate-based identity management in industrial environments, where secure onboarding of devices relies on long-lived and interoperable credentials.…

密码学与安全 · 计算机科学 2025-05-08 Nino Ricchizzi , Christian Schwinne , Jan Pelzl

The sophistication of modern malware, specifically regarding communication with Command and Control (C2) servers, has rendered static blacklist-based defenses obsolete. The use of Domain Generation Algorithms (DGA) allows attackers to…

机器学习 · 计算机科学 2025-12-10 Maria Milena Araujo Felix

This document presents TLS and how to make it secure enough as of 2014 Spring. Of course all the information given here will rot with time. Protocols known as secure will be cracked and will be replaced with better versions. Fortunately we…

密码学与安全 · 计算机科学 2014-07-09 Emmanuel Dreyfus