Invention Grant
- Patent Title: Methods for inspecting security certificates by network security devices to detect and prevent the use of invalid certificates
- Patent Title (中): 网络安全设备检查安全证书以检测和防止使用无效证书的方法
-
Application No.: US13411567Application Date: 2012-03-04
-
Publication No.: US08850576B2Publication Date: 2014-09-30
- Inventor: Guy Guzner , Ami Haviv , Danny Lieblich , Yahav Gal
- Applicant: Guy Guzner , Ami Haviv , Danny Lieblich , Yahav Gal
- Applicant Address: IL Tel Aviv
- Assignee: Check Point Software Technologies Ltd.
- Current Assignee: Check Point Software Technologies Ltd.
- Current Assignee Address: IL Tel Aviv
- Agent Mark M. Friedman
- Main IPC: H04L29/06
- IPC: H04L29/06 ; H04L9/32

Abstract:
Disclosed are methods and media for inspecting security certificates. Methods include the steps of: scanning, by a network security device, messages of a security protocol between a server and a client system; detecting the messages having a security certificate; detecting suspicious security certificates from the messages; and aborting particular sessions of the security protocol associated with the suspicious certificates. Preferably, the step of scanning is performed only on messages of server certificate records. Preferably, the method further includes the step of sending an invalid-certificate notice to the server and the client system. Preferably, the step of detecting the suspicious certificates includes detecting a use of an incorrectly-generated private key for the certificates. Preferably, the step of detecting the suspicious certificates includes detecting an unavailability of revocation information for the certificates. Preferably, the step of detecting the suspicious certificates includes detecting a use of an invalid cryptographic algorithm for the certificates.
Public/Granted literature
Information query