- 1、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
- 4、该文档为VIP文档,如果想要下载,成为VIP会员后,下载免费。
- 5、成为VIP后,下载本文档将扣除1次下载权益。下载后,不支持退款、换文档。如有疑问请联系我们。
- 6、成为VIP后,您将拥有八大权益,权益包括:VIP文档下载权益、阅读免打扰、文档格式转换、高级专利检索、专属身份标志、高级客服、多端互通、版权登记。
- 7、VIP文档为合作方或网友上传,每下载1次, 网站将根据用户上传文档的质量评分、类型等,对文档贡献者给予高额补贴、流量扶持。如果你也想贡献VIP文档。上传文档
查看更多
Mining Your Ps and Qs: Detection of
Widespread Weak Keys in Network Devices
Nadia Heninger† Zakir Durumeric‡ Eric Wustrow‡ J. Alex Halderman‡
† University of California, San Diego ‡ The University of Michigan
nadiah@ {zakir, ewust, jhalderm}@
Abstract expect that today’s widely used operating systems and
RSA and DSA can fail catastrophically when used with server software generate random numbers securely. In this
malfunctioning random number generators, but the extent paper, we test that proposition empirically by examining
to which these problems arise in practice has never been the public keys in use on the Internet.
comprehensively studied at Internet scale. We perform The first component of our study is the most compre-
the largest ever network survey of TLS and SSH servers hensive Internet-wide survey to date of two of the most
and present evidence that vulnerable keys are surprisingly important cryptographic protocols, TLS and SSH (Sec-
widespread. We find that 0.75% of TLS certificates share tion 3.1). By scanning the public IPv4 address space,
keys due to insufficient entropy during key generation, we collected 5.8 million unique TLS certificates from
and we suspect that another 1.70% come from the same 12.8 million hosts and 6.2 million unique SSH host keys
faulty implementations and may be susceptible to com- from 10.2 million hosts. This is 67% more TLS hosts
promise. Even more alarmingly, we are able to obtain than the latest released EFF SSL Observatory dataset [ 18].
RSA private keys for 0.50% of TLS hosts and 0.03% of
您可能关注的文档
- Comparative Analysis of the Impact影响比较分析.pdf
- Comparative Sports Law (Research)比较体育法.pdf
- COMPETITIVE ADVANTAGE_ LOGICAL AND竞争优势与逻辑.pdf
- Comparing CORBA and Web-Services in view of a Service Oriented Architecture英文.pdf
- Complexity Classifications for复杂度分类.pdf
- Computer Systems Organization计算机组装.pdf
- Computerized System for Remote Level Control with Discrete Self-Testing计算机测定.pdf
- Conceptual modeling for the design面向设计念模.pdf
- Conformation of deltorphin-I1 in membrane environment studied by two-dimensional NMR spectroscopy英文资料.pdf
- Consumer Purchase Intention消费者购买意愿.pdf
- Model Order Reduction for Networks网络模型降价.pdf
- Modeling Architectural Pattern Variants建筑模式.pdf
- Modelling the thixotropic behaviour触变行为的模拟.pdf
- Module Assignment for Low Power多资源效率.pdf
- MSc Strategic Marketing市场策略.pdf
- MTH6141 Random Processes, 2018MTH6141随机过程2018.pdf
- Multi-scale Modeling Approach for Detecting Low Observable Targets within Sea Clutter海拔中的目测目标.pdf
- Nanostructured Waste Paper Ash Treated Lateritic Soil and Its California Bearing Ratio Optimization英文资料.pdf
- NANOTECHNOLOGY FOR WATER纳米水技术.pdf
- New and Changed Information新变化信息.pdf
最近下载
- 水库堤坝工程预算方案(3篇).docx VIP
- 《与同学们谈地理》 课件 2025七年级地理上册人教版.pptx VIP
- 100ASK_IMX6ULL-QEMU使用及开发教程_高级用户使用手册.pdf VIP
- 饮食配餐食物交换份法.ppt VIP
- 设备监理师《设备监理基础知识和相关法规》试题及答案.doc VIP
- 贵州省2025年高职院校分类考试招生中职生文化综合英语试题.docx VIP
- 2025年秋统编版语文三年级上册全册同步课件(课标版).pptx
- 南京大学普通天文学课件01天文学史.pptx VIP
- Roland罗兰乐器INTEGRA-7 拥有真实技术的音源INTEGRA-7 说明书用户手册.pdf
- 助学贷款申请表.doc VIP
文档评论(0)