liu.seSearch for publications in DiVA
Change search
Link to record
Permanent link

Direct link
Bruhner, Carl MagnusORCID iD iconorcid.org/0009-0005-9031-6600
Publications (5 of 5) Show all publications
Döberl, M., Freiherr von Wangenheim, Y., Bruhner, C. M., Hasselquist, D., Arlitt, M. & Carlsson, N. (2024). Chain-Sawing: A Longitudinal Analysis of Certificate Chains. In: Proc. IFIP Networking 2024: . Paper presented at 23rd International-Federation-for-Information-Processing (IFIP) Networking Conference (IFIP Networking), Thessaloniki, GREECE, jun 03-06, 2024 (pp. 122-130). IEEE
Open this publication in new window or tab >>Chain-Sawing: A Longitudinal Analysis of Certificate Chains
Show others...
2024 (English)In: Proc. IFIP Networking 2024, IEEE , 2024, p. 122-130Conference paper, Published paper (Refereed)
Abstract [en]

The security and integrity of TLS certificates are essential for ensuring secure transmission over the Internet and protecting millions of people from man-in-the-middle attacks. Certificate Authorities (CAs) play a crucial role in issuing and managing these certificates. This paper presents a longitudinal analysis of certificate chains for popular domains, examining their evolution over time and across different categories. Using publicly available certificate data, primarily from crt.sh, we created a longitudinal dataset of certificate chains for domains from the Tranco top-1M list. After categorizing the certificates based on their type and service category, we analyze a selected set of domains over time and identify the patterns and trends that emerge in their certificate chains. Our analysis reveals several noteworthy trends, including a trend towards shorter certificate chains and fewer paths from domains to root certificates. This implies that the certificate process is becoming more simplified and streamlined. Combined with our observations that there is an increasing use of new CAs and a shift in the types of certificates used that we observe, we expect part of this to be an effect of individual choices made by some popular CAs (e.g., less cross-signings). In general, the observed trends, patterns, and findings capture tradeoffs in overhead, backward compatibility, and security. The quick shifts in some of the observed metrics (e.g., chain lengths) therefore also highlight the importance of continued monitoring and analysis of certificate chains.

Place, publisher, year, edition, pages
IEEE, 2024
Series
IFIP Networking Conference, E-ISSN 1861-2288
National Category
Computer Sciences
Identifiers
urn:nbn:se:liu:diva-208860 (URN)10.23919/IFIPNetworking62109.2024.10619717 (DOI)001303907400018 ()2-s2.0-85202431612 (Scopus ID)9783903176638 (ISBN)9798350390605 (ISBN)
Conference
23rd International-Federation-for-Information-Processing (IFIP) Networking Conference (IFIP Networking), Thessaloniki, GREECE, jun 03-06, 2024
Funder
Wallenberg AI, Autonomous Systems and Software Program (WASP)
Available from: 2024-10-27 Created: 2024-10-27 Last updated: 2025-09-01
Bruhner, C. M., Linnarsson, O., Nemec, M., Arlitt, M. & Carlsson, N. (2024). Monogamous relationships with short-term commitment are the best (for certificate management). In: : . Paper presented at Network and Distributed System Security (NDSS) Symposium 2024.
Open this publication in new window or tab >>Monogamous relationships with short-term commitment are the best (for certificate management)
Show others...
2024 (English)Conference paper, Poster (with or without abstract) (Refereed)
National Category
Computer Sciences
Identifiers
urn:nbn:se:liu:diva-201895 (URN)
Conference
Network and Distributed System Security (NDSS) Symposium 2024
Funder
Wallenberg AI, Autonomous Systems and Software Program (WASP)
Note

Based on the paper "Changing of the Guards: Certificate and Public Key Management on the Internet", Proc. Passive and Active Measurement (PAM) Conference 2022, DOI: 10.1007/978-3-030-98785-5_3

This work was partially supported by the Wallenberg AI, Autonomous Systems and Software Program (WASP) funded by the Knut and Alice Wallenberg Foundation.

Available from: 2024-03-25 Created: 2024-03-25 Last updated: 2025-01-23
Cerenius, D., Kaller, M., Bruhner, C. M., Arlitt, M. & Carlsson, N. (2024). Trust Issue(r)s: Certificate Revocation and Replacement Practices in the Wild. In: Philipp Richter, Vaibhav Bajpai, Esteban Carisimo (Ed.), Passive and Active Measurement: 25th International Conference, PAM 2024. Virtual Event, March 11–13, 2024. Proceedings, Part II.. Paper presented at 25th International Conference on Passive and Active Network Measurement (PAM), Virtual Event, March 11–13, 2024 (pp. 293-321). Cham, Switzerland: Springer Nature, 14538
Open this publication in new window or tab >>Trust Issue(r)s: Certificate Revocation and Replacement Practices in the Wild
Show others...
2024 (English)In: Passive and Active Measurement: 25th International Conference, PAM 2024. Virtual Event, March 11–13, 2024. Proceedings, Part II. / [ed] Philipp Richter, Vaibhav Bajpai, Esteban Carisimo, Cham, Switzerland: Springer Nature, 2024, Vol. 14538, p. 293-321Conference paper, Published paper (Refereed)
Abstract [en]

Every time we use the web, we place our trust in X.509 certificates binding public keys to domain identities. However, for these certificates to be trustworthy, proper issuance, management, and timely revocations (in cases of compromise or misuse) are required. While great efforts have been placed on ensuring trustworthiness in the issuance of new certificates, there has been a scarcity of empirical studies on revocation management. This study offers the first comprehensive analysis of certificate replacements (CRs) of revoked certificates. It provides a head-to-head comparison of the CRs where the replaced certificate was revoked versus not revoked. Leveraging two existing datasets with overlapping timelines, we create a combined dataset containing 1.5 million CRs that we use to unveil valuable insights into the effect of revocations on certificate management. Two key questions guide our research: (1) the influence of revocations on certificate replacement behavior and (2) the effectiveness of revocations in fulfilling their intended purpose. Our statistical analysis reveals significant variations in revocation rates, retention rates, and post-revocation usage, shedding light on differences in Certificate Authorities' (CAs) practices and subscribers' decisions. Notably, a substantial percentage of revoked certificates were either observed or estimated to be used after revocation, raising concerns about key-compromise instances. Finally, our findings highlight shortcomings in existing revocation protocols and practices, emphasizing the need for improvements. We discuss ongoing efforts and potential solutions to address these issues, offering valuable guidance for enhancing the security and integrity of web communications.

Place, publisher, year, edition, pages
Cham, Switzerland: Springer Nature, 2024
Series
Lecture Notes in Computer Science, ISSN 0302-9743, E-ISSN 1611-3349 ; 14538
National Category
Computer Sciences
Identifiers
urn:nbn:se:liu:diva-201892 (URN)10.1007/978-3-031-56252-5_14 (DOI)001209301100014 ()9783031562518 (ISBN)9783031562525 (ISBN)
Conference
25th International Conference on Passive and Active Network Measurement (PAM), Virtual Event, March 11–13, 2024
Funder
Wallenberg AI, Autonomous Systems and Software Program (WASP)
Note

This work was partially supported by the Wallenberg AI, Autonomous Systems and Software Program (WASP) funded by the Knut and Alice Wallenberg Foundation.

Available from: 2024-03-25 Created: 2024-03-25 Last updated: 2024-05-31
Bruhner, C. M., Hasselquist, D. & Carlsson, N. (2023). Bridging the Privacy Gap: Enhanced User Consent Mechanisms on the Web. In: Proc. NDSS Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb @NDSS): . Paper presented at Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb) 2023, San Diego, CA, USA, 3 March, 2023.
Open this publication in new window or tab >>Bridging the Privacy Gap: Enhanced User Consent Mechanisms on the Web
2023 (English)In: Proc. NDSS Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb @NDSS), 2023Conference paper, Published paper (Refereed)
Abstract [en]

In the age of the General Data Protection Regula-tion (GDPR) and the California Consumer Privacy Act (CCPA),privacy and consent control have become even more apparent forevery-day web users. Privacy banners in all shapes and sizes askfor permission through more or less challenging designs and makeprivacy control more of a struggle than they help users’ privacy.In this paper, we present a novel solution expanding the AdvancedData Protection Control (ADPC) mechanism to bridge currentgaps in user data and privacy control. Our solution moves theconsent control to the browser interface to give users a seamlessand hassle-free experience, while at the same time offering contentproviders a way to be legally compliant with legislation. Throughan extensive review, we evaluate previous works and identifycurrent gaps in user data control. We then present a blueprintfor future implementation and suggest features to support privacycontrol online for users globally. Given browser support, thesolution provides a tangible path to effectively achieve legallycompliant privacy and consent control in a user-oriented mannerthat could allow them to again browse the web seamlessly.

National Category
Computer Sciences
Identifiers
urn:nbn:se:liu:diva-199090 (URN)10.14722/madweb.2023.23017 (DOI)1891562878 (ISBN)
Conference
Workshop on Measurements, Attacks, and Defenses for the Web (MADWeb) 2023, San Diego, CA, USA, 3 March, 2023
Note

Best paper runner-up award

Available from: 2023-11-11 Created: 2023-11-11 Last updated: 2023-11-16Bibliographically approved
Bruhner, C. M., Linnarsson, O., Nemec, M., Arlitt, M. & Carlsson, N. (2022). Changing of the Guards: Certificate and Public Key Management on the Internet. In: Hohlfeld, O., Moura, G., Pelsser, C (Ed.), Passive and active measurement (PAM 2022): . Paper presented at 23rd Annual International Passive and Active Measurement (PAM) Conference, SIDN, ELECTR NETWORK, mar 28-30, 2022 (pp. 50-80). , 13210
Open this publication in new window or tab >>Changing of the Guards: Certificate and Public Key Management on the Internet
Show others...
2022 (English)In: Passive and active measurement (PAM 2022) / [ed] Hohlfeld, O., Moura, G., Pelsser, C, 2022, Vol. 13210, p. 50-80Conference paper, Published paper (Refereed)
Abstract [en]

Certificates are the foundation of secure communication over the internet. However, not all certificates are created and managed in a consistent manner and the certificate authorities (CAs) issuing certificates achieve different levels of trust. Furthermore, user trust in public keys, certificates, and CAs can quickly change. Combined with the expectation of 24/7 encrypted access to websites, this quickly evolving landscape has made careful certificate management both an important and challenging problem. In this paper, we first present a novel server-side characterization of the certificate replacement (CR) relationships in the wild, including the reuse of public keys. Our data-driven CR analysis captures management biases, highlights a lack of industry standards for replacement policies, and features successful example cases and trends. Based on the characterization results we then propose an efficient solution to an important revocation problem that currently leaves web users vulnerable long after a certificate has been revoked.

Series
Lecture Notes in Computer Science, ISSN 0302-9743
National Category
Computer Sciences
Identifiers
urn:nbn:se:liu:diva-184851 (URN)10.1007/978-3-030-98785-5_3 (DOI)000787796800003 ()9783030987855 (ISBN)9783030987848 (ISBN)
Conference
23rd Annual International Passive and Active Measurement (PAM) Conference, SIDN, ELECTR NETWORK, mar 28-30, 2022
Funder
Wallenberg AI, Autonomous Systems and Software Program (WASP)Swedish Research Council
Note

Funding Agencies|Swedish Research Council (VR)Swedish Research Council; Wallenberg AI, Autonomous Systems and Software Program (WASP) - Knut and Alice Wallenberg Foundation

Available from: 2022-05-13 Created: 2022-05-13 Last updated: 2024-01-22
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0009-0005-9031-6600