Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates

被引:6
|
作者
Borgolte, Kevin [1 ]
Fiebig, Tobias [2 ]
Hao, Shuang [3 ]
Kruegel, Christopher [1 ]
Vigna, Giovanni [1 ]
机构
[1] UC Santa Barbara, Santa Barbara, CA 93106 USA
[2] Delft Univ Technol, Delft, Netherlands
[3] UT Dallas, Richardson, TX USA
关键词
Domain Name System (DNS); Transport Layer Security (TLS); Secure Sockets Layer (SSL); Certificate Issuance; Domain Validation; Certificate Authority; Automated Certificate Management Environment (ACME); Certificate Transparency; Cloud Computing; Misconfiguration; Trust-based Ecosystem; IP Address Re-Use; Use After Free (UAF);
D O I
10.1145/3232755.3232859
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
引用
收藏
页码:4 / 4
页数:1
相关论文
共 50 条
  • [1] Cloud Strife: Mitigating the Security Risks of Domain-Validated Certificates
    Borgolte, Kevin
    Fiebig, Tobias
    Hao, Shuang
    Kruegel, Christopher
    Vigna, Giovanni
    [J]. 25TH ANNUAL NETWORK AND DISTRIBUTED SYSTEM SECURITY SYMPOSIUM (NDSS 2018), 2018,
  • [2] Mitigating the Security Risks of Unified Communications
    Almeida, Fernando
    Cruz, Jose
    Oliveira, Jose
    [J]. PROCEEDINGS OF 2009 INTERNATIONAL CONFERENCE ON COMPUTER ENGINEERING AND APPLICATIONS, 2009, : 303 - 307
  • [3] The Security Risks of Cloud Computing
    Choi, Myeonggil
    [J]. 2019 22ND IEEE INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (IEEE CSE 2019) AND 17TH IEEE INTERNATIONAL CONFERENCE ON EMBEDDED AND UBIQUITOUS COMPUTING (IEEE EUC 2019), 2019, : 330 - 330
  • [4] Mitigating Threats and Security Metrics in Cloud Computing
    Kar, Jayaprakash
    Mishra, Manoj Ranjan
    [J]. JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2016, 12 (02): : 226 - 233
  • [5] Information security risks management framework - A step towards mitigating security risks in university network
    Joshi, Chanchala
    Singh, Umesh Kumar
    [J]. JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2017, 35 : 128 - 137
  • [6] Security in the Cloud Understanding the Risks of Cloud-as-a-Service
    Peake, Chris
    [J]. 2012 IEEE INTERNATIONAL CONFERENCE ON TECHNOLOGIES FOR HOMELAND SECURITY, 2012, : 336 - 340
  • [7] Risks and Security Requirements for Cloud Environments
    Ziani, Ahmed
    Medouri, Abdellatif
    [J]. PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON SMART CITY APPLICATIONS (SCA'18), 2018,
  • [8] Security Risks and their Management in Cloud Computing
    Khan, Afnan Ullah
    Oriol, Manuel
    Kiran, Mariam
    Jiang, Ming
    Djemame, Karim
    [J]. 2012 IEEE 4TH INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM), 2012,
  • [9] Optimal Network Topologies for Mitigating Security and Epidemic Risks
    Hota, Ashish R.
    Sundaram, Shreyas
    [J]. 2016 54TH ANNUAL ALLERTON CONFERENCE ON COMMUNICATION, CONTROL, AND COMPUTING (ALLERTON), 2016, : 1129 - 1136
  • [10] Mitigating Cyber-Security Risks using MILS
    Liguori, Angelo
    Benedetto, Francesco
    Liguori, Marco
    [J]. 2017 40TH INTERNATIONAL CONFERENCE ON TELECOMMUNICATIONS AND SIGNAL PROCESSING (TSP), 2017, : 1 - 7