{"id":"https://openalex.org/W4403981049","doi":"https://doi.org/10.1145/3646547.3688415","title":"Mutual TLS in Practice: A Deep Dive into Certificate Configurations and Privacy Issues","display_name":"Mutual TLS in Practice: A Deep Dive into Certificate Configurations and Privacy Issues","publication_year":2024,"publication_date":"2024-11-01","ids":{"openalex":"https://openalex.org/W4403981049","doi":"https://doi.org/10.1145/3646547.3688415"},"language":"en","primary_location":{"id":"doi:10.1145/3646547.3688415","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3646547.3688415","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3646547.3688415?download=true","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 ACM on Internet Measurement Conference","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://dl.acm.org/doi/pdf/10.1145/3646547.3688415?download=true","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5015534390","display_name":"Hongying Dong","orcid":"https://orcid.org/0000-0002-7846-2649"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hongying Dong","raw_affiliation_strings":["University of Virginia, Charlottesville, Virginia, USA"],"raw_orcid":"https://orcid.org/0000-0002-7846-2649","affiliations":[{"raw_affiliation_string":"University of Virginia, Charlottesville, Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027344932","display_name":"Yizhe Zhang","orcid":"https://orcid.org/0009-0008-3938-8838"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yizhe Zhang","raw_affiliation_strings":["University of Virginia, Charlottesville, Virginia, USA"],"raw_orcid":"https://orcid.org/0009-0008-3938-8838","affiliations":[{"raw_affiliation_string":"University of Virginia, Charlottesville, Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027908532","display_name":"Hyeonmin Lee","orcid":"https://orcid.org/0000-0003-0361-6532"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hyeonmin Lee","raw_affiliation_strings":["University of Virginia, Charlottesville, Virginia, USA"],"raw_orcid":"https://orcid.org/0000-0003-0361-6532","affiliations":[{"raw_affiliation_string":"University of Virginia, Charlottesville, Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112974277","display_name":"Kevin Du","orcid":"https://orcid.org/0009-0007-7373-3458"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Kevin Du","raw_affiliation_strings":["University of Virginia, Charlottesville, Virginia, USA"],"raw_orcid":"https://orcid.org/0009-0007-7373-3458","affiliations":[{"raw_affiliation_string":"University of Virginia, Charlottesville, Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5096494262","display_name":"Guancheng Tu","orcid":null},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Guancheng Tu","raw_affiliation_strings":["University of Virginia, Charlottesville, Virginia, USA"],"raw_orcid":"https://orcid.org/0009-0006-3254-838X","affiliations":[{"raw_affiliation_string":"University of Virginia, Charlottesville, Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5026356718","display_name":"Yixin Sun","orcid":"https://orcid.org/0000-0001-6650-4373"},"institutions":[{"id":"https://openalex.org/I51556381","display_name":"University of Virginia","ror":"https://ror.org/0153tk833","country_code":"US","type":"education","lineage":["https://openalex.org/I51556381"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yixin Sun","raw_affiliation_strings":["University of Virginia, Charlottesville, Virginia, USA"],"raw_orcid":"https://orcid.org/0000-0001-6650-4373","affiliations":[{"raw_affiliation_string":"University of Virginia, Charlottesville, Virginia, USA","institution_ids":["https://openalex.org/I51556381"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":2.1558,"has_fulltext":true,"cited_by_count":5,"citation_normalized_percentile":{"value":0.9005582,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"214","last_page":"229"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10743","display_name":"Software Testing and Debugging Techniques","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1712","display_name":"Software"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9980000257492065,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.996399998664856,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7364192605018616},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6855453848838806},{"id":"https://openalex.org/keywords/certificate","display_name":"Certificate","score":0.6685339212417603},{"id":"https://openalex.org/keywords/internet-privacy","display_name":"Internet privacy","score":0.4681895971298218},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.0905517041683197}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7364192605018616},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6855453848838806},{"id":"https://openalex.org/C96865113","wikidata":"https://www.wikidata.org/wiki/Q2946816","display_name":"Certificate","level":2,"score":0.6685339212417603},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.4681895971298218},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.0905517041683197}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3646547.3688415","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3646547.3688415","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3646547.3688415?download=true","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 ACM on Internet Measurement Conference","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3646547.3688415","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3646547.3688415","pdf_url":"https://dl.acm.org/doi/pdf/10.1145/3646547.3688415?download=true","source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 ACM on Internet Measurement Conference","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5103986228","display_name":"Collaborative Research: IMR: MM-1B: Automating Privacy-Preserving Data Sharing of Campus Network Traffic Logs","funder_award_id":"2319421","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7378401224","display_name":"SaTC: CORE: Small: Empowering Network Attack Detection with Complex Graph Modeling","funder_award_id":"2154962","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"},{"id":"https://openalex.org/G7923272048","display_name":null,"funder_award_id":"CNS-2154962,CNS-2319421","funder_id":"https://openalex.org/F4320323817","funder_display_name":"Universitas Brawijaya"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"},{"id":"https://openalex.org/F4320323817","display_name":"Universitas Brawijaya","ror":"https://ror.org/01wk3d929"}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W4403981049.pdf","grobid_xml":"https://content.openalex.org/works/W4403981049.grobid-xml"},"referenced_works_count":20,"referenced_works":["https://openalex.org/W1920390248","https://openalex.org/W1976919795","https://openalex.org/W2104899073","https://openalex.org/W2145994642","https://openalex.org/W2236523039","https://openalex.org/W2538863639","https://openalex.org/W2550748725","https://openalex.org/W2745118957","https://openalex.org/W2888934989","https://openalex.org/W2915352631","https://openalex.org/W2988889042","https://openalex.org/W3172154247","https://openalex.org/W3194843666","https://openalex.org/W4206688049","https://openalex.org/W4213190682","https://openalex.org/W4225994596","https://openalex.org/W4245792709","https://openalex.org/W4298051233","https://openalex.org/W4382052771","https://openalex.org/W4387951234"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052"],"abstract_inverted_index":{"Transport":[0],"Layer":[1],"Security":[2],"(TLS)":[3],"is":[4],"widely":[5],"recognized":[6],"as":[7,160,162],"the":[8,32,106,134,139],"essential":[9],"protocol":[10],"for":[11,101],"securing":[12],"Internet":[13],"communications.":[14],"While":[15],"numerous":[16],"studies":[17],"have":[18],"focused":[19],"on":[20,138],"investigating":[21],"server":[22,70,158],"certificates":[23,46,71,78,111,123],"used":[24,79],"in":[25,80,145],"TLS":[26,38,52,85,90],"connections,":[27],"our":[28],"study":[29,137],"delves":[30],"into":[31],"less":[33],"explored":[34],"territory":[35],"of":[36,109,122,142],"mutual":[37,84],"(mTLS)":[39],"where":[40],"both":[41],"parties":[42],"need":[43],"to":[44,47],"provide":[45],"each":[48],"other.":[49],"By":[50,87],"utilizing":[51],"connection":[53,91],"logs":[54],"collected":[55],"from":[56,118],"a":[57],"large":[58],"campus":[59],"network":[60],"over":[61,66,73,81],"23":[62],"months,":[63],"we":[64,104,132],"identify":[65],"2.2":[67],"million":[68,75],"unique":[69,76],"and":[72,96,112,126,128,148,157],"3.4":[74],"client":[77,156],"1.2":[82],"billion":[83],"connections.":[86],"jointly":[88],"analyzing":[89],"data":[92,98],"(e.g.,":[93,99],"port":[94],"numbers)":[95],"certificate":[97],"issuers":[100],"server/client":[102],"certificates),":[103],"quantify":[105],"prevalent":[107],"use":[108],"untrusted":[110],"uncover":[113],"potential":[114],"security":[115],"concerns":[116],"resulting":[117],"misconfigured":[119],"certificates,":[120,159],"sharing":[121],"between":[124,155],"servers":[125],"clients,":[127],"long-expired":[129],"certificates.":[130],"Furthermore,":[131],"present":[133],"first":[135],"in-depth":[136],"wide":[140],"range":[141],"information":[143],"included":[144],"CommonName":[146],"(CN)":[147],"Subject":[149],"Alternative":[150],"Name":[151],"(SAN),":[152],"drawing":[153],"comparison":[154],"well":[161],"revealing":[163],"sensitive":[164],"information.":[165]},"counts_by_year":[{"year":2026,"cited_by_count":2},{"year":2025,"cited_by_count":3}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
