We propose an anomaly detection technique for X.509 certificates utilizing Isolation Forest. This method can be beneficial when compliance testing with X.509 linters proves unsatisfactory, and we seek to identify anomalies beyond standards compliance. The technique is validated on a sample of certificates from Certificate Transparency logs.
翻译:我们提出了一种利用隔离森林进行X.509证书异常检测的技术。当使用X.509格式检查工具进行合规性测试效果不佳,并且我们需要识别超出标准合规性的异常时,该方法将发挥作用。该技术已在来自证书透明度日志的证书样本上得到验证。