DER-based Differential Testing of Certificate V alidation

Donggang Yang, Chu Chen, Pinghong Ren, Xuan Wang · 2023

The authentication of an X.509 digital certificate in the Secure Socket Layer or Transport Layer Security (SSL/TLS) protocol implementation is key to ensuring network security. Therefore, it is important to verify that the digital certificate can be validated correctly. Existing differential testing techniques based on certificate mutation are effective in detecting bugs in certificate validation, but mutation strategy is single. We address this problem by introducing our approach, a differential testing framework based on the mutation of Distinguished Encoding Rules (DER) encoded digital certificates. We obtain the DER-encoded X.509 digital certificate from the network as seed certificates, parse the label, length and value structure of seed certificates, and perform value mutation and Object Identifier (OID) guided mutation according to the parsed structure. We applied our approach on testing 3 popular SSL/TLS implementations, compared with the state-of-the-art differential testing technique (i.e., SADT). Experimental results show that our method is superior to SADT in detecting discrepancies.

Read the paper · More papers on PaperTik