Anomaly Detection in Certificate Transparency Logs

Richard Ostertág,Martin Stanek
2024-05-09
Abstract:We propose an anomaly detection technique for X.509 certificates utilizing Isolation Forest. This method can be beneficial when compliance testing with X.509 linters proves unsatisfactory, and we seek to identify anomalies beyond standards compliance. The technique is validated on a sample of certificates from Certificate Transparency logs.
Cryptography and Security,Machine Learning
What problem does this paper attempt to address?