• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. ParsEval: Evaluation of Parsing Behavior using Real-world Out-in-the-wild X.509 Certificates
 
  • Details
  • Full
Options
2024
Conference Paper
Title

ParsEval: Evaluation of Parsing Behavior using Real-world Out-in-the-wild X.509 Certificates

Abstract
X.509 certificates play a crucial role in establishing secure communication over the internet by enabling authentication and data integrity. Equipped with a rich feature set, the X.509 standard is defined by multiple, comprehensive ISO/IEC documents. Due to its internet-wide usage, there are different implementations in multiple programming languages leading to a large and fragmented ecosystem. This work addresses the research question "Are there user-visible and security-related differences between X.509 certificate parsers?". Relevant libraries offering APIs for parsing X.509 certificates were investigated and an appropriate test suite was developed. From 34 libraries 6 were chosen for further analysis. The X.509 parsing modules of the chosen libraries were called with 186,576,846 different certificates from a real-world dataset and the observed error codes were investigated. This study reveals an anomaly in wolfSSL's X.509 parsing module and that there are fundamental differences in the ecosystem. While related studies nowadays mostly focus on fuzzing techniques resulting in artificial certificates, this study confirms that available X.509 parsing modules differ largely and yield different results, even for real-world out-in-the-wild certificates.
Author(s)
Tatschner, Stefan  
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Peters, Sebastian  orcid-logo
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Heinl, Michael  orcid-logo
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Specht, Tobias
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Newe, Thomas
Mainwork
ARES 2024, 19th International Conference on Availability, Reliability & Security. Proceedings  
Conference
International Conference on Availability, Reliability and Security 2024  
Open Access
DOI
10.1145/3664476.3669935
Additional link
Full text
Language
English
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Keyword(s)
  • ASN.1

  • conformity testing

  • digital certificates

  • parsing

  • TLS libraries

  • X.509

  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024