Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
2
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
Article Reference
Zhang, L., Choffnes, D., Levin, D., Dumitras, T., Mislove, A., Schulman, A., & Wilson, C.
(2014). Analysis of SSL certificate reissues and revocations in the wake of
heartbleed.-Proceedings of the 2014 Conference on Internet Measurement Conference - IMC 14.
doi:10.1145/2663716.2663758
Summary
The analysis on SSL Certificate Reissues and Revocations post-Heartbleed delves into the
intricacies of server authentication and establishing secure communications within Public
Key Infrastructure (PKI). Serving as an essential component, PKI facilitates authentication
for SSL (Secure Sockets Layer) and TLS (Transport Layer Security), thus providing
secure channels for communication on the web while ensuring data integrity, privacy, and
safeguarding billions of connections between browsers and servers daily (Paterson, 2018).
Without these protections, attackers could mimic trusted websites. Zhang, Choffnes, Levin,
Dumitras, Mislove, Schulman, and Wilson (2014) utilized the Heartbleed vulnerability to
illustrate the consequences of delayed administrative responses, identifying weaknesses and
proposing measures to strengthen PKI. The article focuses on examining Heartbleed’s
impact on SSL certificates—specifically reissuing and revoking certificates in response to
vulnerabilities. Through a survey of system administrators, the study assesses their
methods for mitigating SSL certificate vulnerabilities and their patching practices for
server defenses against such issues. Heartbleed itself is a critical bug, found within
OpenSSL’s cryptography library, and exploited data beyond permissible boundaries.
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
3
Zhang et al. (2014) initiated their research by first gathering a sample of SSL certificates,
then filtering the collection via scanning for certificates. Remaining certificates were
checked for revocation, and accessible Certificate Revocation Lists (CRL) were
downloaded. To verify Heartbleed vulnerability on these sites, they dispatched an SSL
message with a pre-specified payload length.
Results
The findings reveal that of the certificates analyzed, 122,832 (28%) were exposed to the
Heartbleed bug, with 10% of these remaining vulnerable even after three weeks. For
reissues and revocations, Zhang et al. (2014) noted that only a limited number of system
administrators reissued certificates using the same key—a contradiction to the intended
purpose of reissue. Interestingly, high-traffic sites were more likely to have their
certificates reissued due to Heartbleed. Only 26% of the vulnerable certificates were
reissued, leaving 73% unaddressed, which poses a risk as these retained private keys could
be compromised if attackers exploited the bug. Heartbleed is challenging to mitigate due to
OpenSSL’s program language, which lacks detection mechanisms or countermeasures
(Wheeler, 2014). Findings from this study provide valuable insights for system
administrators, emphasizing the need for timely patching, reissuing, and revocation to
safeguard against potential threats from attackers targeting SSL certificates.
Discussion
The study by Zhang et al. (2014) effectively demonstrates rigorous methods for evaluating
SSL certificates across various websites, highlighting security lapses that permit
unauthorized access to sensitive information. It underscores the critical role of system
administrators, whose mistakes in reissuing and revoking certificates can expose data to
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
4
attackers. These breaches hold significant implications for businesses, where attackers may
access personal data from customers—such as on e-commerce sites like Amazon or eBay—
potentially leading to massive data leaks. The best defense against these risks is a vigilant
administrative approach, including well-trained system administrators who adhere to
countermeasures, promptly reissue certificates, and diligently monitor vulnerabilities to
minimize attack impacts.
References
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
5
Zhang, L., Choffnes, D., Levin, D., Dumitras, T., Mislove, A., Schulman, A., & Wilson, C.
(2014). Analysis of SSL certificate reissues and revocations in the wake of
heartbleed.-Proceedings of the 2014 Conference on Internet Measurement Conference - IMC 14.
doi:10.1145/2663716.2663758
Paterson, K. (2018). On heartbleed: A hard beginnyng makth a good endyng John Heywood
(1497--1580).-Communications of the ACM,61(3), 108-108. doi:10.1145/3176242
Wheeler, D. A. (2014). Preventing Heartbleed.-Computer,47(8), 80-83.
doi:10.1109/mc.2014.217
Powered by TCPDF (www.tcpdf.org)