skip to main content
10.1145/3232755.3232756acmconferencesArticle/Chapter ViewAbstractPublication PagescommConference Proceedingsconference-collections
invited-talk

Measuring Adoption of Security Additions to the HTTPS Ecosystem

Published:16 July 2018Publication History

ABSTRACT

Web security has been and remains a highly relevant field of security research, which has seen many additional features standardiazed at IETF over the past years.

This talk covers two papers, which in sum provide a conprehensive survey of quantity and quality of adoption of such new security extensions by HTTPS web servers.

The protocols covered are Certificate Transparency (CT) at the PKI/certificate level, HTTP Strict Transport Security (HSTS) and HTTP Public Key Pinning (HPKP) at the HTTP level, Downgrade-Preventing Signaling Cipyher Suite Value (SCSV) at the TLS level, and Certification Authority Authorization (CAA) and TLSA record types. For all these security extensions, we conduct extensive active scans from 2 continents, using IPv4 and IPv6, as well as passive observations from 3 continents. We extensively analyze our results, and discuss adoption of these security extensions by deployment risk, deployment effort, and their relative age, finding low-risk, low-effort extensions deployed the most wide-spread. We consider this a lesson learned for future standardization.

In a subsequent deep-dive in the second paper, we exhaustively analyze the effectiveness of CAA after its effectiveness on Sep 8, 2017. We assess quality and quantity of CAA adoption by servers through holistic active scans, deployment by DNS operators through test domains, and conduct an extensive issuance experiment to scrutinize the rigor of implementation by Certification Authorities (CAs).

Based on [1] and [2].

[1] Johanna Amann, Oliver Gasser, Quirin Scheitle*, Lexi Brent, Georg Carle, and Ralph Holz. 2017. Mission accomplished?: HTTPS security after diginotar. In Proceedings of the 2017 Internet Measurement Conference (IMC '17). ACM, New York, NY, USA, 325--340. DOI: https://doi.org/10.1145/3131365.31314

[2] Quirin Scheitle, Taejoong Chung, Jens Hiller, Oliver Gasser, Johannes Naab, Roland van Rijswijk-Deij, Oliver Hohlfeld, Ralph Holz, Dave Choffnes, Alan Mislove, and Georg Carle. 2018. A First Look at Certification Authority Authorization (CAA). SIGCOMM Comput. Commun. Rev. 48, 2 (May 2018), 10--23. DOI: https://doi.org/10.1145/3213232.3213235

Index Terms

  1. Measuring Adoption of Security Additions to the HTTPS Ecosystem

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Conferences
      ANRW '18: Proceedings of the Applied Networking Research Workshop
      July 2018
      102 pages
      ISBN:9781450355858
      DOI:10.1145/3232755

      Copyright © 2018 Owner/Author

      Permission to make digital or hard copies of part or all of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for third-party components of this work must be honored. For all other uses, contact the Owner/Author.

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 16 July 2018

      Check for updates

      Qualifiers

      • invited-talk
      • Research
      • Refereed limited

      Acceptance Rates

      Overall Acceptance Rate34of58submissions,59%

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader