{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T11:01:09Z","timestamp":1777806069370,"version":"3.51.4"},"reference-count":39,"publisher":"SAGE Publications","issue":"6","license":[{"start":{"date-parts":[[2018,4,11]],"date-time":"2018-04-11T00:00:00Z","timestamp":1523404800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/journals.sagepub.com\/page\/policies\/text-and-data-mining-license"}],"content-domain":{"domain":["journals.sagepub.com"],"crossmark-restriction":true},"short-container-title":["Journal of Computer Security"],"published-print":{"date-parts":[[2018,10,30]]},"abstract":"<jats:p>X.509 certificate parsing and validation is a critical task which has shown consistent lack of effectiveness, with practical attacks being reported with a steady rate during the last 10 years. In this work we analyze the X.509 standard and provide a grammar description of it amenable to the automated generation of a parser with strong termination guarantees, providing unambiguous input parsing. We report the results of analyzing a 11M X.509 certificate dump of the HTTPS servers running on the entire IPv4 space, showing that 21.5% of the certificates in use are syntactically invalid. We compare the results of our parsing against 7 widely used TLS libraries showing that 631k to 1,156k syntactically incorrect certificates are deemed valid by them (5.7%\u201310.5%), including instances with security critical mis-parsings. We prove the criticality of such mis-parsing exploiting one of the syntactic flaws found in existing certificates to perform an impersonation attack.<\/jats:p>","DOI":"10.3233\/jcs-171110","type":"journal-article","created":{"date-parts":[[2018,4,13]],"date-time":"2018-04-13T11:27:41Z","timestamp":1523618861000},"page":"817-849","update-policy":"https:\/\/doi.org\/10.1177\/sage-journals-update-policy","source":"Crossref","is-referenced-by-count":4,"title":["Systematic parsing of X.509: Eradicating security issues with a parse tree"],"prefix":"10.1177","volume":"26","author":[{"given":"Alessandro","family":"Barenghi","sequence":"first","affiliation":[{"name":"Department of Electronics, Information and Bioengineering \u2013 DEIB, Politecnico di Milano, Italy. E-mails:\u00a0,\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicholas","family":"Mainardi","sequence":"additional","affiliation":[{"name":"Department of Electronics, Information and Bioengineering \u2013 DEIB, Politecnico di Milano, Italy. E-mails:\u00a0,\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gerardo","family":"Pelosi","sequence":"additional","affiliation":[{"name":"Department of Electronics, Information and Bioengineering \u2013 DEIB, Politecnico di Milano, Italy. E-mails:\u00a0,\u00a0,\u00a0"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"179","published-online":{"date-parts":[[2018,4,11]]},"reference":[{"key":"ref001","doi-asserted-by":"crossref","unstructured":"C.Adams, S.Farrell, T.Kause and T.Mononen, Internet X.509 Public Key Infrastructure Certificate Management Protocol (CMP),\n                      RFC\n                      4210\n                      (2005).","DOI":"10.17487\/rfc4210"},{"key":"ref002","doi-asserted-by":"crossref","unstructured":"D.Adrian, K.Bhargavan, Z.Durumeric, P.Gaudry, M.Green, J.A.Halderman, N.Heninger, D.Springall, E.Thom\u00e9, L.Valenta, B.VanderSloot, E.Wustrow, S.Z.B\u00e9guelin and P.Zimmermann, Imperfect forward secrecy: How Diffie-Hellman fails in practice, in: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Denver, CO, USA, October 12\u20136, 2015, I.Ray, N.Li and C.Kruegel, eds, ACM, 2015, pp. 5\u201317, ISBN 978-1-4503-3832-5. doi:10.1145\/2810103.2813707.","DOI":"10.1145\/2810103.2813707"},{"key":"ref003","unstructured":"Apple Inc., Secure Transport API, 2016, https:\/\/developer.apple.com\/library\/mac\/documentation\/Security\/Reference\/secureTransportRef\/."},{"key":"ref004","doi-asserted-by":"crossref","unstructured":"A.Barenghi, N.Mainardi and G.Pelosi, A security audit of the OpenPGP format, in: 2017 14th International Symposium on Pervasive Systems, Algorithms and Networks 2017 11th International Conference on Frontier of Computer Science and Technology 2017 Third International Symposium of Creative Computing (ISPAN-FCST-ISCC), S.Jarvis, L.Liu, B.Javadi and S.Guo, eds, IEEE, 2017, pp. 336\u2013343, ISBN 978-1-5386-0841-8. doi:10.1109\/ISPAN-FCST-ISCC.2017.35.","DOI":"10.1109\/ISPAN-FCST-ISCC.2017.35"},{"key":"ref005","doi-asserted-by":"crossref","unstructured":"A.Barenghi, N.Mainardi and G.Pelosi, A novel regular format for X.509 digital certificates, in: Information Technology \u2013 New Generations, S.Latifi, ed. Advances in Intelligent Systems and Computing, Vol. 558, Springer International Publishing, 2018, pp. 133\u2013139, ISBN 978-3-319-54977-4. doi:10.1007\/978-3-319-54978-1.","DOI":"10.1007\/978-3-319-54978-1_18"},{"key":"ref006","doi-asserted-by":"publisher","DOI":"10.1016\/0304-3975(86)90088-5"},{"key":"ref007","doi-asserted-by":"crossref","unstructured":"C.Brubaker, S.Jana, B.Ray, S.Khurshid and V.Shmatikov, Using frankencerts for automated adversarial testing of certificate validation in SSL\/TLS implementations, in: 2014 IEEE Symposium on Security and Privacy, SP 2014, Berkeley, CA, USA, May 18-21, 2014, IEEE Computer Society, 2014, pp. 114\u2013129, ISBN 978-1-4799-4686-0. doi:10.1109\/SP.2014.15.","DOI":"10.1109\/SP.2014.15"},{"key":"ref008","doi-asserted-by":"crossref","unstructured":"D.Cooper, S.Santesson, S.Farrell, S.Boeyen, R.Housley and T.Polk, Internet X.509 Public Key Infrastructure Certificate and CRL,\n                      RFC\n                      5280\n                      (2008).","DOI":"10.17487\/rfc5280"},{"key":"ref009","unstructured":"R.Corbett, GNU Bison \u2013 Release 3.0.4 (2015), https:\/\/www.gnu.org\/software\/bison."},{"key":"ref010","doi-asserted-by":"crossref","unstructured":"Q.Dang, S.Santesson, K.M.Moriarty, D.R.L.Brown and T.Polk, Internet X.509 Public Key Infrastructure: Additional Algorithms and Identifiers for DSA and ECDSA,\n                      RFC\n                      5758\n                      (2010).","DOI":"10.17487\/rfc5758"},{"key":"ref011","unstructured":"A.Delignat-Lavaud, BERserk Vulnerability Part 1: RSA Signature Forgery Attack Due to Incorrect Parsing of ASN.1 Encoded DigestInfo in PKCS1 v1.5, 2014, http:\/\/www.intelsecurity.com\/resources\/wp-berserk-analysis-part-1.pdf."},{"key":"ref012","unstructured":"A.Delignat-Lavaud, BERserk Vulnerability Part 2: Certificate Forgery in Mozilla NSS, 2014, http:\/\/www.intelsecurity.com\/resources\/wp-berserk-analysis-part-2.pdf."},{"key":"ref013","doi-asserted-by":"crossref","unstructured":"Z.Durumeric, J.Kasten, M.Bailey and J.A.Halderman, Analysis of the HTTPS certificate ecosystem, in: Proceedings of the 2013 Internet Measurement Conference, IMC 2013, Barcelona, Spain, October 23\u201325, 2013, K.Papagiannaki, P.K.Gummadi and C.Partridge, eds, ACM, 2013, pp. 291\u2013304, ISBN 978-1-4503-1953-9. doi:10.1145\/2504730.2504755.","DOI":"10.1145\/2504730.2504755"},{"key":"ref014","doi-asserted-by":"crossref","unstructured":"M.Egele, D.Brumley, Y.Fratantonio and C.Kruegel, An empirical study of cryptographic misuse in Android applications, in: 2013 ACM SIGSAC Conference on Computer and Communications Security, CCS\u201913, Berlin, Germany, November 4\u20138, 2013, A.Sadeghi, V.D.Gligor and M.Yung, eds, ACM, 2013, pp. 73\u201384, ISBN 978-1-4503-2477-9. doi:10.1145\/2508859.2516693.","DOI":"10.1145\/2508859.2516693"},{"key":"ref015","unstructured":"Free Software Foundation, Inc., The GnuTLS Transport Layer Security Library, 2016, http:\/\/www.gnutls.org\/."},{"key":"ref016","doi-asserted-by":"crossref","unstructured":"M.Georgiev, S.Iyengar, S.Jana, R.Anubhai, D.Boneh and V.Shmatikov, The most dangerous code in the world: Validating SSL certificates in non-browser software, in: The ACM Conference on Computer and Communications Security, CCS\u201912, Raleigh, NC, USA, October 16\u201318, 2012, T.Yu, G.Danezis and V.D.Gligor, eds, ACM, 2012, pp. 38\u201349, ISBN 978-1-4503-1651-4. doi:10.1145\/2382196.2382204.","DOI":"10.1145\/2382196.2382204"},{"key":"ref017","unstructured":"Google Inc., BoringSSL, 2016, https:\/\/boringssl.googlesource.com\/boringssl\/."},{"key":"ref018","unstructured":"M.A.Harrison, Introduction to Formal Language Theory, Addison-Wesley Longman Publishing Co., Inc., Boston, MA, USA, 1978, ISBN 0201029553."},{"key":"ref019","doi-asserted-by":"crossref","unstructured":"R.Housley, B.Kaliski and J.Schaad, Additional Algorithms and Identifiers for RSA Cryptography for use in the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL),\n                      RFC\n                      4055\n                      (2005).","DOI":"10.17487\/rfc4630"},{"key":"ref020","unstructured":"J.Idle, ANTLR3 C Runtime API and Usage Guide, 2010, http:\/\/www.antlr3.org\/api\/C\/main.html."},{"key":"ref021","unstructured":"International Telecommunication Union, Data networks, Open System Comm.s and Security Recommendations, 2016, https:\/\/www.itu.int\/rec\/T-REC-X."},{"key":"ref022","unstructured":"International Telecommunication Union, Recommendation ITU-T X.509: Open Systems Interconnection \u2013 Public-key and Attribute Certificate Frameworks, 2012, https:\/\/www.itu.int\/rec\/T-REC-X.509-201210-I."},{"key":"ref023","doi-asserted-by":"crossref","unstructured":"D.Kaminsky, M.L.Patterson and L.Sassaman, PKI layer cake: New collision attacks against the global X.509 infrastructure, in: Financial Cryptography and Data Security, 14th International Conference, FC 2010, Tenerife, Canary Islands, January 25\u201328, 2010, Revised Selected Papers, R.Sion, ed. Lecture Notes in Computer Science, Vol. 6052, Springer, 2010, pp. 289\u2013303. ISBN 978-3-642-14576-6. doi:10.1007\/978-3-642-14577-3.","DOI":"10.1007\/978-3-642-14577-3_22"},{"key":"ref024","unstructured":"A.Langley and D.Benjamin, OpenSSL Security Advisory \u2013 Alternative Chains Certificate Forgery, 2015, http:\/\/openssl.org\/news\/secadv\/20150709.txt."},{"key":"ref025","unstructured":"Legion of the Bouncy Castle, Bouncy Castle Java Cryptography APIs, 2016, https:\/\/www.bouncycastle.org\/java.html."},{"key":"ref026","doi-asserted-by":"crossref","unstructured":"S.Leontiev and D.Shefanovski, Using the GOST R 34.10-94, GOST R 34.10-2001, and GOST R 34.11-94 Algorithms with the Internet X.509 Public Key Infrastructure Certificate and CRL Profile,\n                      RFC\n                      4491\n                      (2006).","DOI":"10.17487\/rfc4491"},{"key":"ref027","doi-asserted-by":"crossref","unstructured":"J.Linn, Privacy Enhancement for Internet Electronic Mail: Message Encryption and Authentication,\n                      RFC\n                      1421\n                      (1993).","DOI":"10.17487\/rfc1421"},{"key":"ref028","unstructured":"N.Mainardi, NAXiPP: Not Another X.509 imProper Parser, 2018, https:\/\/github.com\/nicholas-mainardi\/NAXiPP."},{"key":"ref029","unstructured":"M.Marlinspike, Internet Explorer SSL Vulnerability, 2002, https:\/\/moxie.org\/ie-ssl-chain.txt."},{"key":"ref030","unstructured":"M.Marlinspike, Null Prefix Attacks against SSL\/TLS Certificates, 2009, https:\/\/moxie.org\/papers\/null-prefix-attacks.pdf."},{"key":"ref031","unstructured":"Microsoft Corporation, Microsoft Cryptography API, 2016. https:\/\/msdn.microsoft.com\/en-us\/library\/windows\/desktop\/aa380255%28v=vs.85%29.aspx."},{"key":"ref032","unstructured":"Mozilla Foundation, Network Security Services, 2016, https:\/\/wiki.mozilla.org\/NSS."},{"key":"ref033","unstructured":"OpenSSL Foundation, OpenSSL: Cryptography and SSL\/TLS Toolkit, 2016, https:\/\/www.openssl.org\/."},{"key":"ref034","doi-asserted-by":"crossref","unstructured":"T.Parr and K.Fisher, LL(*): The foundation of the ANTLR parser generator, in: Proceedings of the 32nd ACM SIGPLAN Conference on Programming Language Design and Implementation, PLDI 2011, San Jose, CA, USA, June 4\u20138, 2011, M.W.Hall and D.A.Padua, eds, ACM, 2011, pp. 425\u2013436, ISBN 978-1-4503-0663-8. doi:10.1145\/1993498.1993548.","DOI":"10.1145\/1993498.1993548"},{"key":"ref035","doi-asserted-by":"crossref","unstructured":"T.J.Parr and R.W.Quong, Adding semantic and syntactic predicates to LL(k): Pred-LL(k), in: Proceedings of the 5th International Conference on Compiler Construction, CC\u201994, Springer-Verlag, London, UK, 1994, pp. 263\u2013277, ISBN 3-540-57877-3. doi:10.1007\/3-540-57877-3_18.","DOI":"10.1007\/3-540-57877-3_18"},{"key":"ref036","unstructured":"V.Paxson, GNU Fast Lexical Analyzer Generator (FLEX) \u2013 Release 2.6.0 (2015), http:\/\/flex.sourceforge.net."},{"key":"ref037","doi-asserted-by":"crossref","unstructured":"T.Polk, R.Housley and L.Bassham, Algorithms and Identifiers for the Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile,\n                      RFC\n                      3279\n                      (2002).","DOI":"10.17487\/rfc3280"},{"key":"ref038","doi-asserted-by":"crossref","unstructured":"S.Turner, D.R.L.Brown, K.Yiu, R.Housley and T.Polk, Elliptic Curve Cryptography Subject Public Key Information,\n                      RFC\n                      5480\n                      (2009).","DOI":"10.17487\/rfc5480"},{"key":"ref039","unstructured":"N.Vratonjic, J.Freudiger, V.Bindschaedler and J.Hubaux, The inconvenient truth about Web certificates, in: 10th Annual Workshop on the Economics of Information Security, WEIS 2011, George Mason University, Fairfax, VA, USA, June 14\u201315, 2011, 2011."}],"container-title":["Journal of Computer Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-171110","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/full-xml\/10.3233\/JCS-171110","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/journals.sagepub.com\/doi\/pdf\/10.3233\/JCS-171110","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T20:45:15Z","timestamp":1777495515000},"score":1,"resource":{"primary":{"URL":"https:\/\/journals.sagepub.com\/doi\/10.3233\/JCS-171110"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,4,11]]},"references-count":39,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2018,10,30]]}},"alternative-id":["10.3233\/JCS-171110"],"URL":"https:\/\/doi.org\/10.3233\/jcs-171110","relation":{},"ISSN":["0926-227X","1875-8924"],"issn-type":[{"value":"0926-227X","type":"print"},{"value":"1875-8924","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018,4,11]]}}}