×

Methods for inspecting security certificates by network security devices to detect and prevent the use of invalid certificates

  • US 8,850,576 B2
  • Filed: 03/04/2012
  • Issued: 09/30/2014
  • Est. Priority Date: 01/20/2009
  • Status: Active Grant
First Claim
Patent Images

1. A method for inspecting security certificates, the method comprising the steps of by a network security device:

  • (a) detecting messages, of a security protocol between a server and a client system, that have a security certificate;

    (b) detecting suspicious security certificates from said messages, by steps including;

    (i) scanning said messages for an object ID (OID) of a compromised cryptographic hash function, and(ii) scanning said messages for an OID of a certificate extension;

    (iii) upon detecting said OID of said certificate extension in said messages, checking a comment length of said OID of said certificate extension for invalid-certificate criteria, said invalid-certificate criteria including an excessive comment length and at least one non-ASCII character contained in said OID of said certificate extension; and

    (c) aborting sessions of said security protocol associated with said suspicious security certificates that are determined, by said detecting of said suspicious security certificates, to be invalid.

View all claims
  • 0 Assignments
Timeline View
Assignment View
    ×
    ×