{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,13]],"date-time":"2026-06-13T05:41:27Z","timestamp":1781329287396,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,10,15]],"date-time":"2018-10-15T00:00:00Z","timestamp":1539561600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"CRISP"},{"name":"CROSSING","award":["CRC1119"],"award-info":[{"award-number":["CRC1119"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,10,15]]},"DOI":"10.1145\/3243734.3243790","type":"proceedings-article","created":{"date-parts":[[2018,10,16]],"date-time":"2018-10-16T17:38:33Z","timestamp":1539711513000},"page":"2060-2076","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":38,"title":["Domain Validation++ For MitM-Resilient PKI"],"prefix":"10.1145","author":[{"given":"Markus","family":"Brandt","sequence":"first","affiliation":[{"name":"Fraunhofer Institute for Secure Information Technology SIT, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tianxiang","family":"Dai","sequence":"additional","affiliation":[{"name":"Fraunhofer Institute for Secure Information Technology SIT, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Amit","family":"Klein","sequence":"additional","affiliation":[{"name":"Fraunhofer Institute for Secure Information Technology SIT, Jerusalem, Israel"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haya","family":"Shulman","sequence":"additional","affiliation":[{"name":"Fraunhofer Institute for Secure Information Technology SIT, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Michael","family":"Waidner","sequence":"additional","affiliation":[{"name":"Fraunhofer Institute for Secure Information Technology SIT, Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2018,10,15]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Martin Abadi Andrew Birrell Ilya Mironov Ted Wobber and Yinglian Xie. 2013. Global Authentication in an Untrustworthy World.. HotOS .   Martin Abadi Andrew Birrell Ilya Mironov Ted Wobber and Yinglian Xie. 2013. Global Authentication in an Untrustworthy World.. HotOS ."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.42"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2390756.2405036"},{"key":"e_1_3_2_1_5_1","volume-title":"USENIX Security Symposium. 689--706","author":"Aviram Nimrod","year":"2016","unstructured":"Nimrod Aviram , Sebastian Schinzel , Juraj Somorovsky , Nadia Heninger , Maik Dankel , Jens Steube , Luke Valenta , David Adrian , J Alex Halderman , Viktor Dukhovni , 2016 . DROWN: Breaking TLS Using SSLv2 .. In USENIX Security Symposium. 689--706 . Nimrod Aviram, Sebastian Schinzel, Juraj Somorovsky, Nadia Heninger, Maik Dankel, Jens Steube, Luke Valenta, David Adrian, J Alex Halderman, Viktor Dukhovni, et almbox. 2016. DROWN: Breaking TLS Using SSLv2.. In USENIX Security Symposium. 689--706."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1145\/1282427.1282411"},{"key":"e_1_3_2_1_7_1","volume-title":"Transitions: Recommendation for transitioning the use of cryptographic algorithms and key lengths. NIST Special Publication.","author":"Barker E.","year":"2011","unstructured":"E. Barker and A. Roginsky . 2011 . Transitions: Recommendation for transitioning the use of cryptographic algorithms and key lengths. NIST Special Publication. (2011). E. Barker and A. Roginsky. 2011. Transitions: Recommendation for transitioning the use of cryptographic algorithms and key lengths. NIST Special Publication. (2011)."},{"key":"e_1_3_2_1_8_1","volume-title":"Design, Analysis, and Implementation of ARPKI: an Attack-Resilient Public-Key Infrastructure","author":"Basin David","year":"2016","unstructured":"David Basin , Cas Cremers , Tiffany Hyuni-jin, Adrian Perrig , Ralf Sasse , and Pawel Szalachowski . 2016. Design, Analysis, and Implementation of ARPKI: an Attack-Resilient Public-Key Infrastructure . IEEE Transactions on Dependable and Secure Computing ( 2016 ). David Basin, Cas Cremers, Tiffany Hyuni-jin, Adrian Perrig, Ralf Sasse, and Pawel Szalachowski. 2016. Design, Analysis, and Implementation of ARPKI: an Attack-Resilient Public-Key Infrastructure. IEEE Transactions on Dependable and Secure Computing (2016)."},{"key":"e_1_3_2_1_9_1","volume-title":"Using BGP to acquire bogus TLS certificates. HotPETS'17","author":"Birge-Lee Henry","year":"2017","unstructured":"Henry Birge-Lee , Yixin Sun , Annie Edmundson , Jennifer Rexford , and Prateek Mittal . 2017. Using BGP to acquire bogus TLS certificates. HotPETS'17 ( 2017 ). Henry Birge-Lee, Yixin Sun, Annie Edmundson, Jennifer Rexford, and Prateek Mittal. 2017. Using BGP to acquire bogus TLS certificates. HotPETS'17 (2017)."},{"key":"e_1_3_2_1_10_1","unstructured":"CAIDA. {n. d.}. Anonymized Internet Traces Dataset. ({n. d.}).  CAIDA. {n. d.}. Anonymized Internet Traces Dataset. ({n. d.})."},{"key":"e_1_3_2_1_11_1","volume-title":"DTKI: a new formalized PKI with no trusted parties. arXiv preprint arXiv:1408.1023","author":"Cheval Vincent","year":"2014","unstructured":"Vincent Cheval , Mark Ryan , and Jiangshan Yu. 2014. DTKI: a new formalized PKI with no trusted parties. arXiv preprint arXiv:1408.1023 ( 2014 ). Vincent Cheval, Mark Ryan, and Jiangshan Yu. 2014. DTKI: a new formalized PKI with no trusted parties. arXiv preprint arXiv:1408.1023 (2014)."},{"key":"e_1_3_2_1_12_1","unstructured":"Taejoong Chung Roland van Rijswijk-Deij Balakrishnan Chandrasekaran David Choffnes Dave Levin Bruce M Maggs Alan Mislove and Christo Wilson. 2017. A longitudinal end-to-end view of the DNSSEC ecosystem. In USENIX Security .   Taejoong Chung Roland van Rijswijk-Deij Balakrishnan Chandrasekaran David Choffnes Dave Levin Bruce M Maggs Alan Mislove and Christo Wilson. 2017. A longitudinal end-to-end view of the DNSSEC ecosystem. In USENIX Security ."},{"key":"e_1_3_2_1_13_1","volume-title":"DNSSEC Misconfigurations in Popular Domains. In International Conference on Cryptology and Network Security. Springer, 651--660","author":"Dai Tianxiang","year":"2016","unstructured":"Tianxiang Dai , Haya Shulman , and Michael Waidner . 2016 . DNSSEC Misconfigurations in Popular Domains. In International Conference on Cryptology and Network Security. Springer, 651--660 . Tianxiang Dai, Haya Shulman, and Michael Waidner. 2016. DNSSEC Misconfigurations in Popular Domains. In International Conference on Cryptology and Network Security. Springer, 651--660."},{"key":"e_1_3_2_1_14_1","unstructured":"Deploy260. 2014. Email Hijacking. https:\/\/www.internetsociety.org\/blog\/2014\/09\/email-hijacking-new-research-shows-why-we-need-dnssec-now\/. (2014).  Deploy260. 2014. Email Hijacking. https:\/\/www.internetsociety.org\/blog\/2014\/09\/email-hijacking-new-research-shows-why-we-need-dnssec-now\/. (2014)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/138027.138036"},{"key":"e_1_3_2_1_16_1","volume-title":"USENIX Security Symposium","volume":"8","author":"Durumeric Zakir","year":"2013","unstructured":"Zakir Durumeric , Eric Wustrow , and J Alex Halderman . 2013 . ZMap: Fast Internet-wide Scanning and Its Security Applications .. In USENIX Security Symposium , Vol. 8 . 47--53. Zakir Durumeric, Eric Wustrow, and J Alex Halderman. 2013. ZMap: Fast Internet-wide Scanning and Its Security Applications.. In USENIX Security Symposium, Vol. 8. 47--53."},{"key":"e_1_3_2_1_17_1","volume-title":"Sovereign keys: A proposal to make https and email more secure","author":"Eckersley Peter","year":"2011","unstructured":"Peter Eckersley . 2011. Sovereign keys: A proposal to make https and email more secure . Electronic Frontier Foundation , Vol . 18 ( 2011 ). Peter Eckersley. 2011. Sovereign keys: A proposal to make https and email more secure. Electronic Frontier Foundation, Vol. 18 (2011)."},{"key":"e_1_3_2_1_18_1","volume-title":"DEFCON'18","author":"Eckersley P.","year":"2010","unstructured":"P. Eckersley and J. Burns . 2010. An observatory for the SSLiverse . DEFCON'18 . ( 2010 ). P. Eckersley and J. Burns. 2010. An observatory for the SSLiverse. DEFCON'18. (2010)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/2486001.2486018"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2445566.2445568"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/2018436.2018439"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2096149.2096155"},{"key":"e_1_3_2_1_23_1","volume-title":"Path MTU Discovery Considered Harmful. In 38th IEEE International Conference on Distributed Computing Systems, ICDCS 2018","author":"Gohring Matthias","year":"2018","unstructured":"Matthias Gohring , Haya Shulman , and Michael Waidner . 2018 . Path MTU Discovery Considered Harmful. In 38th IEEE International Conference on Distributed Computing Systems, ICDCS 2018 , Vienna, Austria, July 2--6 , 2018. 866--874. Matthias Gohring, Haya Shulman, and Michael Waidner. 2018. Path MTU Discovery Considered Harmful. In 38th IEEE International Conference on Distributed Computing Systems, ICDCS 2018, Vienna, Austria, July 2--6, 2018. 866--874."},{"key":"e_1_3_2_1_24_1","volume-title":"End-Users Get Maneuvered: Empirical Analysis of Redirection Hijacking in Content Delivery Networks. In 27th USENIX Security Symposium (USENIX Security 18)","author":"Hao Shuai","year":"2018","unstructured":"Shuai Hao , Yubao Zhang , Haining Wang , and Angelos Stavrou . 2018 . End-Users Get Maneuvered: Empirical Analysis of Redirection Hijacking in Content Delivery Networks. In 27th USENIX Security Symposium (USENIX Security 18) . USENIX Association. Shuai Hao, Yubao Zhang, Haining Wang, and Angelos Stavrou. 2018. End-Users Get Maneuvered: Empirical Analysis of Redirection Hijacking in Content Delivery Networks. In 27th USENIX Security Symposium (USENIX Security 18). USENIX Association."},{"key":"e_1_3_2_1_25_1","volume-title":"Presented as part of the 21st USENIX Security Symposium (USENIX Security 12). 205--220.","author":"Heninger Nadia","unstructured":"Nadia Heninger , Zakir Durumeric , Eric Wustrow , and J Alex Halderman . 2012. Mining your Ps and Qs: Detection of widespread weak keys in network devices . In Presented as part of the 21st USENIX Security Symposium (USENIX Security 12). 205--220. Nadia Heninger, Zakir Durumeric, Eric Wustrow, and J Alex Halderman. 2012. Mining your Ps and Qs: Detection of widespread weak keys in network devices. In Presented as part of the 21st USENIX Security Symposium (USENIX Security 12). 205--220."},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings. 271--288","author":"Herzberg Amir","year":"2012","unstructured":"Amir Herzberg and Haya Shulman . 2012 . Security of Patched DNS. In Computer Security - ESORICS 2012 - 17th European Symposium on Research in Computer Security, Pisa, Italy, September 10--12, 2012 . Proceedings. 271--288 . Amir Herzberg and Haya Shulman. 2012. Security of Patched DNS. In Computer Security - ESORICS 2012 - 17th European Symposium on Research in Computer Security, Pisa, Italy, September 10--12, 2012. Proceedings. 271--288."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2013.6682711"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2523649.2523662"},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings. 219--236","author":"Herzberg Amir","year":"2013","unstructured":"Amir Herzberg and Haya Shulman . 2013 . Vulnerable Delegation of DNS Resolution. In Computer Security - ESORICS 2013 - 18th European Symposium on Research in Computer Security, Egham, UK, September 9--13, 2013 . Proceedings. 219--236 . Amir Herzberg and Haya Shulman. 2013. Vulnerable Delegation of DNS Resolution. In Computer Security - ESORICS 2013 - 18th European Symposium on Research in Computer Security, Egham, UK, September 9--13, 2013. Proceedings. 219--236."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068856"},{"key":"e_1_3_2_1_31_1","first-page":"1679","article-title":"Taxonomy of the Snowden Disclosures","volume":"72","author":"Hu Margaret","year":"2015","unstructured":"Margaret Hu . 2015 . Taxonomy of the Snowden Disclosures . Wash & Lee L. Rev. , Vol. 72 (2015), 1679 -- 1989 . Margaret Hu. 2015. Taxonomy of the Snowden Disclosures. Wash & Lee L. Rev., Vol. 72 (2015), 1679--1989.","journal-title":"Wash & Lee L. Rev."},{"key":"e_1_3_2_1_32_1","volume-title":"Black Hat conference. http:\/\/www.blackhat.com\/presentations\/bh-jp-08\/bh-jp-08-Kaminsky\/BlackHat-Japan-08-Kaminsky-DNS08-BlackOps.pdf.","author":"Kaminsky Dan","year":"2008","unstructured":"Dan Kaminsky . 2008 . It's the End of the Cache As We Know It . In Black Hat conference. http:\/\/www.blackhat.com\/presentations\/bh-jp-08\/bh-jp-08-Kaminsky\/BlackHat-Japan-08-Kaminsky-DNS08-BlackOps.pdf. Dan Kaminsky. 2008. It's the End of the Cache As We Know It. In Black Hat conference. http:\/\/www.blackhat.com\/presentations\/bh-jp-08\/bh-jp-08-Kaminsky\/BlackHat-Japan-08-Kaminsky-DNS08-BlackOps.pdf."},{"key":"e_1_3_2_1_33_1","unstructured":"Kernel.org. 2011. Linux Kernel Documentation. http:\/\/www.kernel.org\/doc\/Documentation\/networking\/ip-sysctl.txt. (2011).  Kernel.org. 2011. Linux Kernel Documentation. http:\/\/www.kernel.org\/doc\/Documentation\/networking\/ip-sysctl.txt. (2011)."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/2488388.2488448"},{"key":"e_1_3_2_1_35_1","volume-title":"Counting in the Dark: Caches Discovery and Enumeration in the Internet. In The 47th IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN) .","author":"Klein Amit","year":"2017","unstructured":"Amit Klein , Haya Shulman , and Michael Waidner . 2017 . Counting in the Dark: Caches Discovery and Enumeration in the Internet. In The 47th IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN) . Amit Klein, Haya Shulman, and Michael Waidner. 2017. Counting in the Dark: Caches Discovery and Enumeration in the Internet. In The 47th IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN) ."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Amit Klein Haya Shulman and Michael Waidner. 2017. Internet-Wide Study of DNS Cache Injections. In INFOCOM .  Amit Klein Haya Shulman and Michael Waidner. 2017. Internet-Wide Study of DNS Cache Injections. In INFOCOM .","DOI":"10.1109\/INFOCOM.2017.8057202"},{"key":"e_1_3_2_1_37_1","unstructured":"Jeffrey Knockel and Jedidiah R Crandall. 2014. Counting Packets Sent Between Arbitrary Internet Hosts.. In FOCI .  Jeffrey Knockel and Jedidiah R Crandall. 2014. Counting Packets Sent Between Arbitrary Internet Hosts.. In FOCI ."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/2504730.2504734"},{"key":"e_1_3_2_1_40_1","unstructured":"Sharon Goldberg. 2018. The myetherwallet.com hijack and why it's risky to hold cryptocurrency in a webapp. https:\/\/medium.com\/@goldbe\/the-myetherwallet-com-hijack-and-why-its-risky-to-hold-cryptocurrency-in-a-webapp-261131fad278. (2018).  Sharon Goldberg. 2018. The myetherwallet.com hijack and why it's risky to hold cryptocurrency in a webapp. https:\/\/medium.com\/@goldbe\/the-myetherwallet-com-hijack-and-why-its-risky-to-hold-cryptocurrency-in-a-webapp-261131fad278. (2018)."},{"key":"e_1_3_2_1_41_1","volume-title":"Applied Cryptography and Network Security (ACNS)","author":"Shulman Haya","unstructured":"Haya Shulman and Michael Waidner . 2014. Fragmentation Considered Leaking: Port Inference for DNS Poisoning . In Applied Cryptography and Network Security (ACNS) , Lausanne, Switzerland . Springer . Haya Shulman and Michael Waidner. 2014. Fragmentation Considered Leaking: Port Inference for DNS Poisoning. In Applied Cryptography and Network Security (ACNS), Lausanne, Switzerland. Springer."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24174-6_1"},{"key":"e_1_3_2_1_43_1","unstructured":"Haya Shulman and Michael Waidner. 2017. One Key to Sign Them All Considered Vulnerable: Evaluation of DNSSEC in the Internet.. In NSDI. 131--144.   Haya Shulman and Michael Waidner. 2017. One Key to Sign Them All Considered Vulnerable: Evaluation of DNSSEC in the Internet.. In NSDI. 131--144."},{"key":"e_1_3_2_1_44_1","volume-title":"The hitchhiker's guide to DNS cache poisoning. Security and Privacy in Communication Networks","author":"Son Sooel","unstructured":"Sooel Son and Vitaly Shmatikov . 2010. The hitchhiker's guide to DNS cache poisoning. Security and Privacy in Communication Networks . Springer , 466--483. Sooel Son and Vitaly Shmatikov. 2010. The hitchhiker's guide to DNS cache poisoning. Security and Privacy in Communication Networks. Springer, 466--483."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660355"},{"key":"e_1_3_2_1_46_1","volume-title":"Perspectives: Improving SSH-style Host Authentication with Multi-Path Probing. In USENIX Annual Technical Conference","volume":"8","author":"Wendlandt Dan","year":"2008","unstructured":"Dan Wendlandt , David G Andersen , and Adrian Perrig . 2008 . Perspectives: Improving SSH-style Host Authentication with Multi-Path Probing. In USENIX Annual Technical Conference , Vol. 8 . 321--334. Dan Wendlandt, David G Andersen, and Adrian Perrig. 2008. Perspectives: Improving SSH-style Host Authentication with Multi-Path Probing. In USENIX Annual Technical Conference, Vol. 8. 321--334."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2010.10"}],"event":{"name":"CCS '18: 2018 ACM SIGSAC Conference on Computer and Communications Security","location":"Toronto Canada","acronym":"CCS '18","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3243734.3243790","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3243734.3243790","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:08:18Z","timestamp":1750212498000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3243734.3243790"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10,15]]},"references-count":45,"alternative-id":["10.1145\/3243734.3243790","10.1145\/3243734"],"URL":"https:\/\/doi.org\/10.1145\/3243734.3243790","relation":{},"subject":[],"published":{"date-parts":[[2018,10,15]]},"assertion":[{"value":"2018-10-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}