2014 IEEE Symposium on Security and Privacy 2014
DOI: 10.1109/sp.2014.12
|View full text |Cite
|
Sign up to set email alerts
|

When HTTPS Meets CDN: A Case of Authentication in Delegated Service

Abstract: Content Delivery Network (CDN) and Hypertext Transfer Protocol Secure (HTTPS) are two popular but independent web technologies, each of which has been well studied individually and independently. This paper provides a systematic study on how these two work together. We examined 20 popular CDN providers and 10,721 of their customer web sites using HTTPS. Our study reveals various problems with the current HTTPS practice adopted by CDN providers, such as widespread use of invalid certificates, private key sharin… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

1
73
0

Year Published

2015
2015
2022
2022

Publication Types

Select...
5
2

Relationship

0
7

Authors

Journals

citations
Cited by 93 publications
(74 citation statements)
references
References 24 publications
1
73
0
Order By: Relevance
“…In Figure 1 we present the usage distribution of commercial CDN providers among the 32K most popular websites (according to Alexa website-popularity rank [5]). 1 Line 1 of Figure 1 confirms earlier studies [24], [27]: most websites do not use CDNs, and furthermore, use of CDN declines for less-popular sites (from the 2000 place onwards). Note that larger organizations often use their own infrastructure instead of an external CDN provider.…”
Section: Cdn Popularitysupporting
confidence: 83%
See 3 more Smart Citations
“…In Figure 1 we present the usage distribution of commercial CDN providers among the 32K most popular websites (according to Alexa website-popularity rank [5]). 1 Line 1 of Figure 1 confirms earlier studies [24], [27]: most websites do not use CDNs, and furthermore, use of CDN declines for less-popular sites (from the 2000 place onwards). Note that larger organizations often use their own infrastructure instead of an external CDN provider.…”
Section: Cdn Popularitysupporting
confidence: 83%
“…In particular, the CDN market is dominated by a few providers [24], [27], resulting in a less-competitive market and hence higher costs. To distribute content in face of strong DoS attacks, CDNon-Demand deploys proxy servers on multiple Infrastructureas-a-Service (IaaS) cloud providers, optimizing resource use to minimize expenses.…”
Section: Cdn Popularitymentioning
confidence: 99%
See 2 more Smart Citations
“…Other empirical studies of the TLS ecosystem have focused on certificate validation libraries [66], non-browser TLS libraries [67], the interaction of HTTPS with content-delivery networks [68], and TLS implementations in Android apps [69], [70]. Again, these efforts all found widespread weaknesses.…”
Section: B Empirical Studies Of Https and Tlsmentioning
confidence: 99%