Can a TLS certificate be phishy?

Kaspar Hageman, Egon Kidmose, René Rydhof Hansen, Jens Myrup Pedersen

Research output: Contribution to book/anthology/report/conference proceedingArticle in proceedingResearchpeer-review

4 Citations (Scopus)
180 Downloads (Pure)

Abstract

This paper investigates the potential of using digital certificates for the detection of phishing domains. This i motivated by phishing domains that have started to abuse the (erroneous) trust of the public in browser padloc symbols, and by the large-scale adoption of the Certificate Transparency (CT) framework. This publicl accessible evidence trail of Transport Layer Security (TLS) certificates has made the TLS landscape mor transparent than ever. By comparing samples of phishing, popular benign, and non-popular benign domains we provide insight into the TLS certificates issuance behavior for phishing domains, focusing on the selectio of the certificate authority, the validation level of the certificates, and the phenomenon of certificate sharin among phishing domains. Our results show that phishing domains gravitate to a relatively small selection o certificate authorities, and disproportionally to cPanel, and tend to rely on certificates with a low, and cheap validation level. Additionally, we demonstrate that the vast majority of certificates issued for phishing domain cover more than only phishing domains. These results suggest that a more pro-active role of CAs and puttin more emphasis on certificate revocation can have a crucial impact in the defense against phishing attacks.

Original languageEnglish
Title of host publicationProceedings of the 18th International Conference on Security and Cryptography, SECRYPT 2021
EditorsSabrina De Capitani di Vimercati, Pierangela Samarati
Number of pages12
PublisherSCITEPRESS Digital Library
Publication date2021
Pages38-49
ISBN (Electronic)978-989-758-524-1
DOIs
Publication statusPublished - 2021
Event18th International Conference on Security and Cryptography, SECRYPT 2021 - Virtual, Online
Duration: 6 Jul 20218 Jul 2021

Conference

Conference18th International Conference on Security and Cryptography, SECRYPT 2021
CityVirtual, Online
Period06/07/202108/07/2021
SponsorInstitute for Systems and Technologies of Information, Control and Communication (INSTICC)
SeriesInternational Conference on Security and Cryptography - SECRYPT - Proceedings
ISSN2184-7711

Bibliographical note

Funding Information:
This research is carried out under the SecDNS project, funded by Innovation Fund Denmark. We thank Cen-sys.io for sharing their CT log data with us, and we are thankful for the APWG for granting us access to their eCX platform.

Publisher Copyright:
Copyright © 2021 by SCITEPRESS – Science and Technology Publications, Lda. All rights reserved

Keywords

  • Certificate Transparency
  • Digital Certificate
  • Phishing
  • TLS

Fingerprint

Dive into the research topics of 'Can a TLS certificate be phishy?'. Together they form a unique fingerprint.

Cite this