Please use this identifier to cite or link to this item:
http://arks.princeton.edu/ark:/88435/dsp01k3569766z
Title: | Certificate Authority Authorization Record Collection and Analysis |
Authors: | Poor, Kenny |
Advisors: | Mittal, Prateek |
Department: | Electrical and Computer Engineering |
Class Year: | 2024 |
Abstract: | Certificates are important parts of the Web Public Key Infrastructure that allow domains to prove their identity to connecting clients. Mis-issuance of certificates by Certificate Authorities (CAs) or malicious attack of this process could have disastrous security consequences and incur severe financial loss, for example, from cryptocurrency theft. Certificate Transparency (CT) is a system adopted in 2013 that gives public visibility into certificate issuance for monitoring. CT logs record the issuance of a certificate. Certificate Authority Authorization (CAA) records allow domain owners choose CAs they trust to get certificates. However, there are insufficient checking whether CAs issue certificates according to CAA standards; and no study has investigated the intersection of CT logs and CAA compliance and usage. Our work implemented a comprehensive CT log monitor that performs basic CAA record compliance analysis when a new certificate issuance is recorded in a CT log, overcoming the significant time delay between new entries collection and CAA records checking. Our distributed system design also addresses the incompleteness in collection present in other CT monitors. By comprehensively monitoring all publicly trusted CT logs, we hope to achieve a global view of the CAA record landscape and to gather rate of CAA and DNSSEC usage by domains. Currently, our algorithm requests 300 CT log entries per second with response rate at 50-75%, and asynchronously sends DNS CAA Record requests for domains associated with these entries. Our data analysis revealed the general landscape of CAA records, such as the frequency of certificate issuance by the CAs, whether CAA records significantly change the distribution etc. |
URI: | http://arks.princeton.edu/ark:/88435/dsp01k3569766z |
Type of Material: | Princeton University Senior Theses |
Language: | en |
Appears in Collections: | Electrical and Computer Engineering, 1932-2024 |
Files in This Item:
File | Description | Size | Format | |
---|---|---|---|---|
POOR-KENNY-THESIS.pdf | 1.02 MB | Adobe PDF | Request a copy |
Items in Dataspace are protected by copyright, with all rights reserved, unless otherwise indicated.