One year of SSL internet measurement

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Over the years, SSL/TLS has become an essential part of internet security. As such, it should offer robust and state-of-the-art security, in particular for HTTPS, its first application. Theoretically, the protocol allows for a trade-off between secure algorithms and decent performance. Yet in practice, servers do not always support the latest version of the protocol, nor do they all enforce strong cryptographic algorithms. To assess the quality of HTTPS servers in the wild, we enumerated HTTPS servers on the internet in July 2010 and July 2011. We sent several stimuli to the servers to gather detailed information. We then analysed some parameters of the collected data and looked at how they evolved. We also focused on two subsets of TLS hosts within our measure: the trusted hosts (possessing a valid certificate at the time of the probing) and the EV hosts (presenting a trusted, socalled Extended Validation certificate). Our contributions rely on this methodology: the stimuli we sent, the criteria we studied and the subsets we focused on. Moreover, even if EV servers present a somewhat improved certificate quality over the TLS hosts, we show they do not offer overall high quality sessions, which could and should be improved.

Original languageEnglish
Title of host publicationProceedings - 28th Annual Computer Security Applications Conference, ACSAC 2012
Pages11-20
Number of pages10
DOIs
Publication statusPublished - 1 Dec 2012
Externally publishedYes
Event28th Annual Computer Security Applications Conference, ACSAC 2012 - Orlando, FL, United States
Duration: 3 Dec 20127 Dec 2012

Publication series

NameACM International Conference Proceeding Series

Conference

Conference28th Annual Computer Security Applications Conference, ACSAC 2012
Country/TerritoryUnited States
CityOrlando, FL
Period3/12/127/12/12

Keywords

  • Certificates
  • HTTPS
  • Internet measure
  • SSL/TLS
  • X.509

Fingerprint

Dive into the research topics of 'One year of SSL internet measurement'. Together they form a unique fingerprint.

Cite this