Off-Path Attacks Against PKI

Dai, Tianxiang and Shulman, Haya and Waidner, Michael (2018) Off-Path Attacks Against PKI. In: CCS '18: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security :. ACM, New York, pp. 2213-2215. ISBN 9781450356930

Full text not available from this repository.

Abstract

The security of Internet-based applications fundamentally relies on the trustworthiness of Certificate Authorities (CAs). We practically demonstrate for the first time that even a very weak attacker, namely, an off-path attacker, can effectively subvert the trustworthiness of popular commercially used CAs. We demonstrate an attack against one popular CA which uses Domain Validation (DV) for authenticating domain ownership. The attack exploits DNS Cache Poisoning and tricks the CA into issuing fraudulent certificates for domains the attacker does not legitimately own -- namely certificates binding the attacker's public key to a victim domain.

Item Type:
Contribution in Book/Report/Proceedings
ID Code:
229631
Deposited By:
Deposited On:
28 May 2025 13:25
Refereed?:
No
Published?:
Published
Last Modified:
28 May 2025 23:13