Saved in:
Bibliographic Details
Main Authors: Janovsky, Adam, Jancar, Jan, Svenda, Petr, Chmielewski, Łukasz, Michalik, Jiri, Matyas, Vashek
Format: Preprint
Published: 2023
Subjects:
Online Access:https://arxiv.org/abs/2311.17603
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866929404785983488
author Janovsky, Adam
Jancar, Jan
Svenda, Petr
Chmielewski, Łukasz
Michalik, Jiri
Matyas, Vashek
author_facet Janovsky, Adam
Jancar, Jan
Svenda, Petr
Chmielewski, Łukasz
Michalik, Jiri
Matyas, Vashek
contents Products certified under security certification frameworks such as Common Criteria undergo significant scrutiny during the costly certification process. Yet, critical vulnerabilities, including private key recovery (ROCA, Minerva, TPM-Fail...), get discovered in certified products with high assurance levels. Furthermore, assessing which certified products are impacted by such vulnerabilities is complicated due to the large amount of unstructured certification-related data and unclear relationships between the certified products. To address these problems, we conducted a large-scale automated analysis of Common Criteria certificates. We trained unsupervised models to learn which vulnerabilities from NIST's National Vulnerability Database impact existing certified products and how certified products reference each other. Our tooling automates the analysis of tens of thousands of certification-related documents, extracting machine-readable features where manual analysis is unattainable. Further, we identify the security requirements that are associated with products being affected by fewer and less severe vulnerabilities. This indicates which aspects of certification correlate with higher security. We demonstrate how our tool can be used for better vulnerability mitigation on four case studies of known, high-profile vulnerabilities. All tools and continuously updated results are available at https://seccerts.org
format Preprint
id arxiv_https___arxiv_org_abs_2311_17603
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle sec-certs: Examining the security certification practice for better vulnerability mitigation
Janovsky, Adam
Jancar, Jan
Svenda, Petr
Chmielewski, Łukasz
Michalik, Jiri
Matyas, Vashek
Cryptography and Security
Products certified under security certification frameworks such as Common Criteria undergo significant scrutiny during the costly certification process. Yet, critical vulnerabilities, including private key recovery (ROCA, Minerva, TPM-Fail...), get discovered in certified products with high assurance levels. Furthermore, assessing which certified products are impacted by such vulnerabilities is complicated due to the large amount of unstructured certification-related data and unclear relationships between the certified products. To address these problems, we conducted a large-scale automated analysis of Common Criteria certificates. We trained unsupervised models to learn which vulnerabilities from NIST's National Vulnerability Database impact existing certified products and how certified products reference each other. Our tooling automates the analysis of tens of thousands of certification-related documents, extracting machine-readable features where manual analysis is unattainable. Further, we identify the security requirements that are associated with products being affected by fewer and less severe vulnerabilities. This indicates which aspects of certification correlate with higher security. We demonstrate how our tool can be used for better vulnerability mitigation on four case studies of known, high-profile vulnerabilities. All tools and continuously updated results are available at https://seccerts.org
title sec-certs: Examining the security certification practice for better vulnerability mitigation
topic Cryptography and Security
url https://arxiv.org/abs/2311.17603