4 papers · 1 filter
A Call to Reconsider Certification Authority Authorization (CAA)
Pouyan Fotouhi Tehrani, Raphael Hiesgen, Thomas C. Schmidt +1
Certification Authority Authentication (CAA) is a safeguard against illegitimate certificate issuance. We show how shortcomings in CAA concepts and operational aspects undermine it…
The Age of DDoScovery: An Empirical Comparison of Industry and Academic DDoS Assessments
Raphael Hiesgen, Marcin Nawrocki, Marinho Barcellos +14
Motivated by the impressive but diffuse scope of DDoS research and reporting, we undertake a multistakeholder (joint industry-academic) analysis to seek convergence across the best…
From the Beginning: Key Transitions in the First 15 Years of DNSSEC
Eric Osterweil, Pouyan Fotouhi Tehrani, Thomas C. Schmidt +1
When the global rollout of the DNS Security Extensions (DNSSEC) began in 2005, a first-of-its-kind trial started: The complexity of a core Internet protocol was magnified in favor…
Do CAA, CT, and DANE Interlink in Certificate Deployments? A Web PKI Measurement Study
Pouyan Fotouhi Tehrani, Raphael Hiesgen, Teresa Lübeck +2
Integrity and trust on the web build on X.509 certificates. Misuse or misissuance of these certificates threaten the Web PKI security model, which led to the development of several…