{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,21]],"date-time":"2025-11-21T18:08:23Z","timestamp":1763748503614,"version":"3.45.0"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,11,12]],"date-time":"2021-11-12T00:00:00Z","timestamp":1636675200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"German Federal Ministry of Education and Research","award":["ATHENE"],"award-info":[{"award-number":["ATHENE"]}]},{"name":"Hessen State Min- istry for Higher Education, Research and Arts","award":["ATHENE"],"award-info":[{"award-number":["ATHENE"]}]},{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft","doi-asserted-by":"publisher","award":["SFB1119"],"award-info":[{"award-number":["SFB1119"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,11,12]]},"DOI":"10.1145\/3460120.3484815","type":"proceedings-article","created":{"date-parts":[[2021,11,13]],"date-time":"2021-11-13T12:05:33Z","timestamp":1636805133000},"page":"1421-1440","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":14,"title":["Let's Downgrade Let's Encrypt"],"prefix":"10.1145","author":[{"given":"Tianxiang","family":"Dai","sequence":"first","affiliation":[{"name":"ATHENE Center &amp; Fraunhofer SIT, Darmstadt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haya","family":"Shulman","sequence":"additional","affiliation":[{"name":"ATHENE Center &amp; Fraunhofer SIT, Darmstadt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Waidner","sequence":"additional","affiliation":[{"name":"ATHENE Center; TU Darmstadt; &amp; Fraunhofer SIT, Darmstadt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,11,13]]},"reference":[{"key":"e_1_3_2_2_1_1","unstructured":"Louis Poinsignon. 2018. BGP leaks and cryptocurrencies . https:\/\/blog.cloudflare.com\/bgp-leaks-and-crypto-currencies\/"},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363192"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC.2009.5202224"},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1030194.1015499"},{"key":"e_1_3_2_2_5_1","volume-title":"et almbox","author":"Austein Rob","year":"2017","unstructured":"Rob Austein, Steven Bellovin, Russ Housley, Stephen Kent, Warren Kumari, Doug Montgomery, Chris Morrow, Sandy Murphy, Keyur Patel, John Scudder, et almbox. 2017. RFC 8205-BGPsec Protocol Specification. (2017)."},{"key":"e_1_3_2_2_6_1","volume-title":"Mar.","author":"Barnes R","year":"2019","unstructured":"R Barnes, J Hoffman-Andrews, D McCarney, and J Kasten. [n.d.]. RFC 8555: Automatic Certificate Management Environment (ACME), Mar. 2019. Proposed Standard ( [n.,d.])."},{"volume-title":"27th $$USENIX$$ Security Symposium ($$USENIX$$ Security 18). 833--849.","author":"Birge-Lee Henry","key":"e_1_3_2_2_7_1","unstructured":"Henry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford, and Prateek Mittal. 2018. Bamboozling certificate authorities with $$BGP$$. In 27th $$USENIX$$ Security Symposium ($$USENIX$$ Security 18). 833--849."},{"key":"e_1_3_2_2_8_1","volume-title":"Experiences Deploying Multi-Vantage-Point Domain Validation at Let's Encrypt. USENIX Security (December","author":"Birge-Lee Henry","year":"2021","unstructured":"Henry Birge-Lee, Liang Wang, Daniel McCarney, Roland Shoemaker, Jennifer Rexford, and Prateek Mittal. 2021. Experiences Deploying Multi-Vantage-Point Domain Validation at Let's Encrypt. USENIX Security (December 2021)."},{"key":"e_1_3_2_2_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363197"},{"key":"e_1_3_2_2_10_1","unstructured":"Peter Boothe James Hiebert and Randy Bush. 2006. Short-lived prefix hijacking on the Internet. NANOG."},{"key":"e_1_3_2_2_11_1","unstructured":"Markus Brandt Tianxiang Dai Amit Klein Haya Shulman and Michael Waidner. 2018. Domain Validation"},{"volume-title":"MitM-Resilient PKI. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. ACM","author":"For","key":"e_1_3_2_2_12_1","unstructured":"For MitM-Resilient PKI. In Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security. ACM, 2060--2076."},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"crossref","unstructured":"Randy Bush and Rob Austein. 2013. The resource public key infrastructure (RPKI) to router protocol.","DOI":"10.17487\/rfc6810"},{"key":"e_1_3_2_2_14_1","unstructured":"CAIDA. 2021. BGP Stream . https:\/\/bgpstream.caida.org\/"},{"volume-title":"26th $$USENIX$$ Security Symposium ($$USENIX$$ Security 17) . 1307--1322.","author":"Chung Taejoong","key":"e_1_3_2_2_15_1","unstructured":"Taejoong Chung, Roland van Rijswijk-Deij, Balakrishnan Chandrasekaran, David Choffnes, Dave Levin, Bruce M Maggs, Alan Mislove, and Christo Wilson. 2017. A Longitudinal, End-to-End View of the $$DNSSEC$$ Ecosystem. In 26th $$USENIX$$ Security Symposium ($$USENIX$$ Security 17) . 1307--1322."},{"key":"e_1_3_2_2_16_1","unstructured":"D. Madory. 2018. Recent Routing Incidents: Using BGP to Hijack DNS and more . https:\/\/www.lacnic.net\/innovaportal\/file\/3207\/1\/dougmadory_lacnic_30_rosario.pdf"},{"key":"e_1_3_2_2_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3452296.3472933"},{"volume-title":"30th $$USENIX$$ Security Symposium ($$USENIX$$ Security 21) . 3147--3164.","author":"Dai Tianxiang","key":"e_1_3_2_2_18_1","unstructured":"Tianxiang Dai, Philipp Jeitner, Haya Shulman, and Michael Waidner. 2021 b. The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet Resources. In 30th $$USENIX$$ Security Symposium ($$USENIX$$ Security 21) . 3147--3164."},{"key":"e_1_3_2_2_19_1","volume-title":"April","author":"Damas Joao","year":"2013","unstructured":"Joao Damas, Michael Graff, and Paul Vixie. 2013. Extension mechanisms for DNS (EDNS (0)). IETF RFC6891, April (2013)."},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMSWA.2008.4554428"},{"key":"e_1_3_2_2_21_1","doi-asserted-by":"publisher","DOI":"10.5038\/2378-0789.3.1.1050"},{"key":"e_1_3_2_2_22_1","unstructured":"Frank Denis. 2013. The GOOGLE.RW Hijack . http:\/\/labs.umbrella.com\/2013\/10\/25\/google-rw-hijack-nobody-else-noticed\/."},{"key":"e_1_3_2_2_23_1","unstructured":"EFF the Electronic Frontier Foundation. [n.d.]. Certbot . https:\/\/certbot.eff.org\/"},{"key":"e_1_3_2_2_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417884"},{"key":"e_1_3_2_2_25_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-40667-1_15"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2013.6682711"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2018.00070"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"crossref","unstructured":"A Hubert and R Van Mook. 2009. Measures for making DNS more resilient against forged answers. In RFC 5452. RFC.","DOI":"10.17487\/rfc5452"},{"volume-title":"30th $$USENIX$$ Security Symposium ($$USENIX$$ Security 21). 3165--3182.","author":"Jeitner Philipp","key":"e_1_3_2_2_29_1","unstructured":"Philipp Jeitner and Haya Shulman. 2021. Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS. In 30th $$USENIX$$ Security Symposium ($$USENIX$$ Security 21). 3165--3182."},{"key":"e_1_3_2_2_30_1","unstructured":"Josh Aas and Daniel McCarney and and Roland Shoemaker. 2020. Multi-Perspective Validation Improves Domain Validation Security . https:\/\/letsencrypt.org\/2020\/02\/19\/multi-perspective-validation.html"},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2008.06.012"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2398776.2398780"},{"volume-title":"28th $$USENIX$$ Security Symposium ($$USENIX$$ Security 19) . 1063--1080.","author":"Klein Amit","key":"e_1_3_2_2_33_1","unstructured":"Amit Klein and Benny Pinkas. 2019. From $$IP$$$$ID$$ to Device $$ID$$ and $$KASLR$$ Bypass. In 28th $$USENIX$$ Security Symposium ($$USENIX$$ Security 19) . 1063--1080."},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3419394.3423622"},{"key":"e_1_3_2_2_35_1","volume-title":"USENIX Security symposium","volume":"1","author":"Lad Mohit","year":"2006","unstructured":"Mohit Lad, Daniel Massey, Dan Pei, Yiguo Wu, Beichuan Zhang, and Lixia Zhang. 2006. PHAS: A Prefix Hijack Alert System.. In USENIX Security symposium , Vol. 1. 3."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2659897"},{"key":"e_1_3_2_2_37_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC3785"},{"key":"e_1_3_2_2_38_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC8205"},{"key":"e_1_3_2_2_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3345653"},{"key":"e_1_3_2_2_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417280"},{"key":"e_1_3_2_2_41_1","doi-asserted-by":"crossref","unstructured":"D McPherson V Gill D Walton and A Retana. 2002. RFC3345: Border Gateway Protocol (BGP) Persistent Route Oscillation Condition.","DOI":"10.17487\/rfc3345"},{"key":"e_1_3_2_2_42_1","volume-title":"Exploiting Speculative Execution (Spectre) via JavaScript. Advanced Microkernel Operating Systems","author":"Noack Lucas","year":"2018","unstructured":"Lucas Noack and Tobias Reichert. 2018. Exploiting Speculative Execution (Spectre) via JavaScript. Advanced Microkernel Operating Systems (2018), 11."},{"key":"e_1_3_2_2_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813708"},{"key":"e_1_3_2_2_44_1","first-page":"14","article-title":"CoDNS: Improving DNS Performance and Reliability via Cooperative Lookups","volume":"4","author":"Park KyoungSoo","year":"2004","unstructured":"KyoungSoo Park, Vivek S Pai, Larry L Peterson, and Zhe Wang. 2004. CoDNS: Improving DNS Performance and Reliability via Cooperative Lookups.. In OSDI , Vol. 4. 14--14.","journal-title":"OSDI"},{"key":"e_1_3_2_2_45_1","unstructured":"Tashi Phuntsho. 2019. How to Install an RPKI Validator . https:\/\/labs.ripe.net\/Members\/tashi_phuntsho_3\/how-to-install-an-rpki-validator"},{"key":"e_1_3_2_2_46_1","unstructured":"Lindsey Poole and Vivek S Pai. 2006. ConfiDNS: Leveraging Scale and History to Improve DNS Security.. In WORLDS ."},{"key":"e_1_3_2_2_47_1","unstructured":"RIPE NCC. 2021. RIS Raw Data . https:\/\/www.ripe.net\/analyse\/internet-measurements\/routing-information-service-ris\/ris-raw-data"},{"key":"e_1_3_2_2_48_1","unstructured":"S. Goldberg. 2018. The myetherwallet.com hijack and why it's risky to hold cryptocurrency in a webapp . https:\/\/medium.com\/@goldbe\/the-myetherwallet-com-hijack-and-why-its-risky-to-hold-cryptocurrency-in-a-webapp-261131fad278"},{"key":"e_1_3_2_2_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-07536-5_31"},{"volume-title":"14th $$USENIX$$ Symposium on Networked Systems Design and Implementation ($$NSDI$$ 17). 131--144.","author":"Shulman Haya","key":"e_1_3_2_2_50_1","unstructured":"Haya Shulman and Michael Waidner. 2017. One key to sign them all considered vulnerable: Evaluation of DNSSEC in the internet. In 14th $$USENIX$$ Symposium on Networked Systems Design and Implementation ($$NSDI$$ 17). 131--144."},{"key":"e_1_3_2_2_51_1","volume-title":"Securing Internet Applications from Routing Attacks. arXiv preprint arXiv:2004.09063","author":"Sun Yixin","year":"2020","unstructured":"Yixin Sun, Maria Apostolaki, Henry Birge-Lee, Laurent Vanbever, Jennifer Rexford, Mung Chiang, and Prateek Mittal. 2020. Securing Internet Applications from Routing Attacks. arXiv preprint arXiv:2004.09063 (2020)."},{"key":"e_1_3_2_2_52_1","unstructured":"University of Oregon Route Views Project. 2021. Route Views Project . http:\/\/www.routeviews.org\/routeviews\/"},{"key":"e_1_3_2_2_53_1","first-page":"5131","article-title":"Analyzing BIND DNS server selection algorithm","volume":"6","author":"Wang Zheng","year":"2010","unstructured":"Zheng Wang, Xin Wang, and Xiaodong Lee. 2010. Analyzing BIND DNS server selection algorithm. International Journal of Innovative Computing, Information and Control , Vol. 6, 11 (2010), 5131--5142.","journal-title":"International Journal of Innovative Computing, Information and Control"},{"key":"e_1_3_2_2_54_1","volume-title":"Improving SSH-style Host Authentication with Multi-path Network Probing. In USENIX Annual Technical Conference .","author":"Wendlandt D","year":"2008","unstructured":"D Wendlandt, D Andersen, and A Perrigo Perspectives. 2008. Improving SSH-style Host Authentication with Multi-path Network Probing. In USENIX Annual Technical Conference ."},{"key":"e_1_3_2_2_55_1","doi-asserted-by":"publisher","DOI":"10.1145\/2185376.2185387"},{"key":"e_1_3_2_2_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.45"}],"event":{"name":"CCS '21: 2021 ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Virtual Event Republic of Korea","acronym":"CCS '21"},"container-title":["Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484815","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460120.3484815","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T20:47:31Z","timestamp":1763498851000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460120.3484815"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,12]]},"references-count":56,"alternative-id":["10.1145\/3460120.3484815","10.1145\/3460120"],"URL":"https:\/\/doi.org\/10.1145\/3460120.3484815","relation":{},"subject":[],"published":{"date-parts":[[2021,11,12]]},"assertion":[{"value":"2021-11-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}