Measurement and Analysis
- f Private Key Sharing in
Measurement and Analysis of Private Key Sharing in the HTTPS - - PowerPoint PPT Presentation
Measurement and Analysis of Private Key Sharing in the HTTPS Ecosystem Frank Cangialosi, Taejoong Chung, David Choffnes, Dave Levin, Bruce M. Maggs, Alan Mislove, Christo Wilson How do we know with whom we are communicating? How do we know
Certificate
Certificate
Certificate
Certificate
Certificate
Certificate Certificate
Certificate Certificate
Certificate Certificate
Certificate Certificate
Certificate Certificate
Certificate Certificate
Certificate
Certificate
Certificate
Certificate
Certificate
Certificate
Domain Domain Domain Domain Certificate IP Addr Domain Domain Domain Domain Certificate IP Addr
IPv4 Scan Domain Domain Domain Domain Certificate IP Addr Domain Domain Domain Domain Certificate IP Addr
Domain Domain Domain Domain Certificate IP Addr Domain Domain Domain Domain Certificate IP Addr
Domain Domain Domain Domain Certificate Domain Domain Domain Domain Certificate IP Addr IP Addr
IPv4 Scan Domain Domain Domain Domain Certificate Domain Domain Domain Domain Certificate IP Addr IP Addr
Domain Domain Domain Domain Certificate Domain Domain Domain Domain Certificate IP Addr IP Addr
Domain Domain Domain Domain Certificate Domain Domain Domain Domain Certificate IP Addr IP Addr
Domain Domain Domain Domain Certificate Domain Domain Domain Domain Certificate IP Addr IP Addr
Domain Domain Domain Domain Domain IP Addr IP Addr
Domain Domain Domain Domain Domain IP Addr IP Addr
Domain Domain Domain Domain Domain IP Addr IP Addr
google.com google.co.uk google.com youtube.com nestle.com friskies.com whitehouse.gov whitehouse.com
google.com google.co.uk google.de zagat.com golang.org
google.com google.co.uk google.de zagat.com golang.org whois Registrant Email: Admin Email: Tech Email: dns-admin@google.com dns-admin@google.com dns-admin@google.com
google.com google.co.uk google.de zagat.com golang.org dns-admin@google.com dns-admin@google.com dns-admin@google.com
google.com google.co.uk google.de zagat.com golang.org dns-admin@google.com dns-admin@google.com dns-admin@google.com
google.com google.co.uk google.de zagat.com golang.org Registrant Email: Admin Email: Tech Email: dns-admin@google.com dns-admin@google.com dns-admin@google.com whois whois dns-admin@google.com dns-admin@google.com dns-admin@google.com
google.com google.co.uk google.de zagat.com golang.org
dns-admin@google.com dns-admin@google.com dns-admin@google.com
google.com google.co.uk google.de zagat.com golang.org
whois whois dns-admin@google.com dns-admin@google.com dns-admin@google.com
google.com google.co.uk google.de zagat.com golang.org
Registrant Email: Admin Email: Tech Email: dns-admin@google.com dns-admin@google.com dns-admin@google.com whois whois dns-admin@google.com dns-admin@google.com dns-admin@google.com
google.com google.co.uk google.de zagat.com golang.org dns-admin@google.com dns-admin@google.com dns-admin@google.com
google.com google.co.uk google.de zagat.com golang.org
Domain Organization
Domain Domain Domain Domain Domain IP Addr IP Addr
Domain Domain Domain
Domain Domain Org Domain Org Domain Domain Org IP Addr IP Addr
Domain Domain Domain
Domain Domain Org Domain Org Domain Domain Org Host Host
Domain Domain Domain
Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
0.2 0.4 0.6 0.8 1 1 10 102 103 104 105 CDF Number of Third-Party Hosting Providers Used Organizations
0.2 0.4 0.6 0.8 1 1 10 102 103 104 105 CDF Number of Third-Party Hosting Providers Used Organizations
0.2 0.4 0.6 0.8 1 1 10 102 103 104 105 CDF Number of Third-Party Hosting Providers Used Organizations
0.2 0.4 0.6 0.8 1 1 10 102 103 104 105 CDF Number of Third-Party Hosting Providers Used Organizations
0.2 0.4 0.6 0.8 1 1 10 102 103 104 105 CDF Number of Third-Party Hosting Providers Used Organizations
0.2 0.4 0.6 0.8 1 200k 400k 600k 800k 1M Fraction of Domains Hosted
Alexa Site Rank (bins of 10,000) At least one key shared All keys shared
0.2 0.4 0.6 0.8 1 200k 400k 600k 800k 1M Fraction of Domains Hosted
Alexa Site Rank (bins of 10,000) At least one key shared All keys shared
0.2 0.4 0.6 0.8 1 200k 400k 600k 800k 1M Fraction of Domains Hosted
Alexa Site Rank (bins of 10,000) At least one key shared All keys shared
0.2 0.4 0.6 0.8 1 200k 400k 600k 800k 1M Fraction of Domains Hosted
Alexa Site Rank (bins of 10,000) At least one key shared All keys shared
0.2 0.4 0.6 0.8 1 200k 400k 600k 800k 1M Fraction of Domains Hosted
Alexa Site Rank (bins of 10,000) At least one key shared All keys shared
popular websites
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
100 101 102 103 104 105 106 100 101 102 103 104 105 106 Number of Distinct Customers Served Rank-Order Third-Party Hosting Providers
100 101 102 103 104 105 106 100 101 102 103 104 105 106 Number of Distinct Customers Served Rank-Order Third-Party Hosting Providers
100 101 102 103 104 105 106 100 101 102 103 104 105 106 Number of Distinct Customers Served Rank-Order Third-Party Hosting Providers
secureserver.net unifiedlayer.com amazonaws.com Cloud Flare Inc. Rackspace Hosting akamaitechnologies.com
266,110 151,628 117.229 78,369 54,158 15,440 … … #Organizations Hosting provider 277,891 175,089 122,158 87,077 63,418 22,671 … #Domains
100 101 102 103 104 105 106 100 101 102 103 104 105 106 Number of Distinct Customers Served Rank-Order Third-Party Hosting Providers
secureserver.net unifiedlayer.com amazonaws.com Cloud Flare Inc. Rackspace Hosting akamaitechnologies.com
266,110 151,628 117.229 78,369 54,158 15,440 … … #Organizations Hosting provider 277,891 175,089 122,158 87,077 63,418 22,671 … #Domains
100 101 102 103 104 105 106 100 101 102 103 104 105 106 Number of Distinct Customers Served Rank-Order Third-Party Hosting Providers
secureserver.net unifiedlayer.com amazonaws.com Cloud Flare Inc. Rackspace Hosting akamaitechnologies.com
266,110 151,628 117.229 78,369 54,158 15,440 … … #Organizations Hosting provider 277,891 175,089 122,158 87,077 63,418 22,671 … #Domains
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
Domain Domain Domain Domain Domain Org Domain Org Domain Domain Org Host Host Host Org Host Org Host Org Domain Org
0.2 0.4 0.6 0.8 1 100 101 102 103 104 105 106 Cumulative Fraction of Domains’ Keys Acquired Number of Hosting Providers Compromised Alexa Top 1k Alexa Top 1m All Domains
0.2 0.4 0.6 0.8 1 100 101 102 103 104 105 106 Cumulative Fraction of Domains’ Keys Acquired Number of Hosting Providers Compromised Alexa Top 1k Alexa Top 1m All Domains
0.2 0.4 0.6 0.8 1 100 101 102 103 104 105 106 Cumulative Fraction of Domains’ Keys Acquired Number of Hosting Providers Compromised Alexa Top 1k Alexa Top 1m All Domains 60% of Top 1K, same provider
0.2 0.4 0.6 0.8 1 100 101 102 103 104 105 106 Cumulative Fraction of Domains’ Keys Acquired Number of Hosting Providers Compromised Alexa Top 1k Alexa Top 1m All Domains 60% of Top 1K, same provider
0.2 0.4 0.6 0.8 1 100 101 102 103 104 105 106 Cumulative Fraction of Domains’ Keys Acquired Number of Hosting Providers Compromised Alexa Top 1k Alexa Top 1m All Domains >40% of all sites, 10 providers 60% of Top 1K, same provider
0.2 0.4 0.6 0.8 1 100 101 102 103 104 105 106 Cumulative Fraction of Domains’ Keys Acquired Number of Hosting Providers Compromised Alexa Top 1k Alexa Top 1m All Domains
>40% of all sites, 10 providers 60% of Top 1K, same provider
keys for 86% of orgs
popular websites
Website acquires Third-party acquires
Website acquires Third-party acquires
Website acquires Third-party acquires
Website acquires Third-party acquires
Website acquires Third-party acquires
Website acquires Third-party acquires
Website acquires Third-party acquires
58.4% of Alexa Top 10K 33.0% of all domains
0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced
0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced
0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced CloudFlare revocations
0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced 0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced Outsourced (w/o CF) CloudFlare revocations
0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced 0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced Outsourced (w/o CF) CloudFlare revocations Slightly more thorough
0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced 0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced Outsourced (w/o CF) CloudFlare revocations 10 days to react! Slightly more thorough
0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced 0.75 0.8 0.85 0.9 0.95 1 04/07 04/11 04/15 04/19 04/23 04/27 05/01 05/05 Fraction of Certificates Not Revoked Date Self-managed Outsourced Outsourced (w/o CF) CloudFlare revocations 10 days to react! Slightly more thorough
0.2 0.4 0.6 0.8 1 0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 1 CDF of Hosting Providers Fraction of Heartbleed-vulnerable Certificates Revoked Self-managed Outsourced
0.2 0.4 0.6 0.8 1 0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 1 CDF of Hosting Providers Fraction of Heartbleed-vulnerable Certificates Revoked Self-managed Outsourced
0.2 0.4 0.6 0.8 1 0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 1 CDF of Hosting Providers Fraction of Heartbleed-vulnerable Certificates Revoked Self-managed Outsourced
0.2 0.4 0.6 0.8 1 0.1 0.2 0.3 0.4 0.5 0.6 0.7 0.8 0.9 1 CDF of Hosting Providers Fraction of Heartbleed-vulnerable Certificates Revoked Self-managed Outsourced
job of revoking
keys for 86% of orgs
popular websites