Contour: A Practical System for Binary Transparency

12/22/2017
by   Mustafa Al-Bassam, et al.
0

Transparency is crucial in security-critical applications that rely on authoritative information, as it provides a robust mechanism for holding these authorities accountable for their actions. A number of solutions have emerged in recent years that provide transparency in the setting of certificate issuance, and Bitcoin provides an example of how to enforce transparency in a financial setting. In this work we shift to a new setting, the distribution of software package binaries, and present a system for so-called "binary transparency." Our solution, Contour, uses proactive methods for providing transparency, privacy, and availability, even in the face of persistent man-in-the-middle attacks. We also demonstrate, via benchmarks and a test deployment for the Debian software repository, that Contour is the only system for binary transparency that satisfies the efficiency and coordination requirements that would make it possible to deploy today.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
11/20/2017

Software Distribution Transparency and Auditability

A large user base relies on software updates provided through package ma...
research
11/04/2022

Rescuing the End-user systems from Vulnerable Applications using Virtualization Techniques

In systems owned by normal end-users, many times security attacks are mo...
research
06/23/2023

Full Transparency in DBI frameworks

Following the increasing trends of malicious applications or cyber threa...
research
11/09/2020

Think Global, Act Local: Gossip and Client Audits in Verifiable Data Structures

In recent years, there has been increasing recognition of the benefits o...
research
05/13/2019

Private Queries on Public Certificate Transparency Data

Despite increasing advancements in today's information exchange infrastr...
research
06/01/2020

Serverless End Game: Disaggregation enabling Transparency

For many years, the distributed systems community has struggled to smoot...
research
04/07/2021

Serverless Predictions: 2021-2030

Within the next 10 years, advances on resource disaggregation will enabl...

Please sign up or login with your details

Forgot password? Click here to reset