Hinajeros, Francisca; Almenares-Mendoza, Florina; Gomila, Patricia Arias-Cabarcos Josep-Lluis Ferrer; Marín-López, Andrés RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security. Journal Article In: IEEE Transactions on Information Forensics and Security , vol. 13, iss. 8, pp. 1975-1988, 2018, ISSN: 1556-6013. Abstract | Links | BibTeX | Tags: certificate validation, mobile applications, risk assessment, trust validation2018
@article{almenarez009b,
title = {RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security. },
author = {Francisca Hinajeros and Florina Almenares-Mendoza and Patricia Arias-Cabarcos Josep-Lluis Ferrer Gomila and Andrés Marín-López},
doi = {https://doi.org/10.1109/tifs.2018.2807788},
issn = {1556-6013},
year = {2018},
date = {2018-02-19},
urldate = {2018-02-19},
journal = {IEEE Transactions on Information Forensics and Security },
volume = {13},
issue = {8},
pages = {1975-1988},
abstract = {Digital certificates, based on X.509 PKI standard, are located at the core of many security mechanisms implemented in services and applications. However, the usage of certificates has revealed flaws in the certificate validation process (e.g., possibility of unavailable or non-updated data). This fact implies security risks that are not assessed. In order to address these issues that such flaws entail, we propose a novel probabilistic approach for quantitative risk assessment in X.509 PKI, together with trust management when there is uncertainty. We have evaluated our risk assessment approach and demonstrated its usage, considering as a use case the secure installation of mobile applications. The results show that our approach provides more granularity, appropriate values according to the impact, and relevant information in the risk calculation than other approaches.},
keywords = {certificate validation, mobile applications, risk assessment, trust validation},
pubstate = {published},
tppubtype = {article}
}
Publications
RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security. Journal Article In: IEEE Transactions on Information Forensics and Security , vol. 13, iss. 8, pp. 1975-1988, 2018, ISSN: 1556-6013.2018