Skip to main content
QUICK REVIEW

[论文解读] Shedding Light on the Adoption of Let's Encrypt

Antonis Manousis, Roy Ragsdale|arXiv (Cornell University)|Nov 2, 2016
Advanced Malware Detection Techniques参考文献 8被引用 15
一句话总结

本文利用1800万条证书透明度日志及互补数据源,分析了Let's Encrypt证书在现实世界中的采用与使用情况。研究发现,尽管Let's Encrypt推动了HTTPS的普及——尤其在新兴市场及知名度较低的域名中——但近一半颁发的证书未被使用,且存在越来越多滥用迹象,如用于拼写错误劫持(typosquatting)和恶意软件托管,凸显了关键的安全与配置挑战。

ABSTRACT

Let's Encrypt is a new entrant in the Certificate Authority ecosystem that offers free and automated certificate signing. It is visionary in its commitment to Certificate Transparency. In this paper, we shed light on the adoption patterns of Let's Encrypt "in the wild" and inform the future design and deployment of this exciting development in the security landscape. We analyze acquisition patterns of certificates as well as their usage and deployment trends in the real world. To this end, we analyze data from Certificate Transparency Logs containing records of more then 18 million certificates. We also leverage other sources like Censys, Alexa's historic records, Geolocation databases, and VirusTotal. We also perform active HTTPS measurements on the domains owning Let's Encrypt certificates. Our analysis of certificate acquisition shows that (1) the impact of Let's Encrypt is particularly visible in Western Europe; (2) Let's Encrypt has the potential to democratize HTTPS adoption in countries that are recent entrants to Internet adoption; (3) there is anecdotal evidence of popular domains quitting their previously untrustworthy or expensive CAs in order to transition to Let's Encrypt; and (4) there is a "heavy tailed" behavior where a small number of domains acquire a large number of certificates. With respect to usage, we find that: (1) only 54% of domains actually use the Let's Encrypt certificates they have procured; (2) there are many non-trivial incidents of server misconfigurations; and (3) there is early evidence of use of Let's Encrypt certificates for typosquatting and for malware-laden sites.

研究动机与目标

  • 理解Let’s Encrypt证书在真实环境中获取的地理分布、人口统计及行为模式。
  • 评估Let’s Encrypt证书的实际部署与使用情况,而不仅限于颁发行为。
  • 识别由免费且自动化的证书颁发所引发的配置错误、无效证书及潜在滥用向量。
  • 为Let’s Encrypt、网站管理员、浏览器厂商及终端用户提供未来设计改进的依据。

提出的方法

  • 从证书透明度(CT)日志中收集并分析1800万条证书记录,以识别使用Let’s Encrypt证书的域名。
  • 通过外部数据源验证发现结果:使用Censys获取证书元数据,使用Alexa评估域名流行度,使用VirusTotal检测恶意软件,使用地理位置数据库进行国家层面的归属分析。
  • 对持有Let’s Encrypt证书的域名进行主动HTTPS测量,以评估其在现实世界中的部署状态。
  • 追踪证书获取趋势,以检测突发流量(flash crowds)和长尾行为。
  • 通过检查已部署证书中常见的TLS配置错误,评估配置质量。
  • 使用启发式方法检测潜在滥用行为,如基于域名名称模式和声誉评分的拼写错误劫持与恶意软件托管。

实验结果

研究问题

  • RQ1Let’s Encrypt在地理区域上的采用情况如何分布,特别是在互联网采用率较低的国家?
  • RQ2实际在生产环境中部署并使用的已颁发证书占多大比例?
  • RQ3在网站中部署Let’s Encrypt证书时是否存在显著的配置错误?
  • RQ4Let’s Encrypt在多大程度上被用于恶意目的,如拼写错误劫持或恶意软件托管?
  • RQ5证书获取的行为模式如何,例如是否存在长尾分布或突发流量?

主要发现

  • Let’s Encrypt显著推动了HTTPS的普及,尤其在阿根廷、乌克兰和南非等国家表现突出——其使用率比全球平均水平高出5倍。
  • 仅有54%获得Let’s Encrypt证书的域名实际在生产环境中部署了证书,表明存在广泛闲置或未使用的情况。
  • 大量已部署的证书存在非微不足道的配置错误,表明亟需更优的工具和指导。
  • 已有早期但日益增长的滥用证据,包括使用Let’s Encrypt证书进行拼写错误劫持和托管含恶意软件的网站。
  • 少数域名占用了不成比例的大量证书,表明存在显著的长尾获取模式。
  • 主动测量至关重要,因为仅靠证书透明度日志无法验证证书是否实际被使用或配置正确。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。