1 / 5100%
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
1
Analysis of SSL Certificate Reissues and Revocations
James Jarbob
Liberty University
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
2
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
Article Reference
Zhang, L., Choffnes, D., Levin, D., Dumitras, T., Mislove, A., Schulman, A., & Wilson, C.
(2014). Analysis of SSL certificate reissues and revocations in the wake of
heartbleed.-Proceedings of the 2014 Conference on Internet Measurement Conference - IMC 14.
doi:10.1145/2663716.2663758
Summary
In the study of the Analysis of SSL Certificates and Reissues in the Wake of Heartbleed
was a search in server authentication and the secure communications within them. The PKI
(Public Key Infrastructure) allows for server authentication and is a big component for the SSL
(Secure Sockets Layer) and the TLS (Transport Layer Security) which allows for a secure
communication to the website and provide privacy and data integrity and protects billions of
communications sessions between browsers and servers on a daily basis (Paterson 2018).
Without these in place it would be possible for an attacker to be able to act like a trusted website.
In this article the authors Zhang, Choffnes, Levin, Dumitras, Mislove, Schulman, Wilson (2014)
use the Heartbleed security bug to examine how slow administrators can form a weak security
and find different ways to protect the Public Key Infrastructure. The purpose of the article is to
study the Heartbleed vulnerability and how SSL certificates are issued and revoked in the
response to a vulnerability as well as surveying system administrators to see how they combat
the different vulnerabilities targeting the SSL certificates and how they work on patching their
servers when fighting against these problems. Heartbleed is a serious security bug that is found
in the OpenSSL cryptography library that is used by the Transport Layer Security (TLS) that
allowed for more data to be accessed and read than what should have been.
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
3
The authors Zhang et al. (2014) started their study by first getting a collection of SSL
certificates and then used the scans that were collected to filter the certificates. The remaining
certificates leftover were checked to see if they have been revoked, the reachable Certificate
Revocation List (CRL) URL’s were then downloaded. To test if the sites were at risk to the
Heartbleed vulnerability Zhang et al. (2014) were able to send an SSL message with a specific
payload length to test for the vulnerability.
Results
The end results of the research show that 122,832 (28%) of the certificates that were
examined were vulnerable to the Heartbleed security bug and after three weeks 10% of the
122,832 certificates that were vulnerable still did nothing to combat the threat. For the certificate
reissues and revocations Zhang et al. (2014) observed that only a small amount of system
administrators was reissued with the same key for the certificates which defeats the purpose of
reissued a certificate and the higher ranked the site is the more likely it was for their certificate to
be reissued because of the Heartbleed security bug. Of all the certificates that were vulnerable
only 26% were found to of been reissued and the remaining 73% were not reissued (Zhang et al.,
2014), the reason these certificates were vulnerable is that the private keys that they hold could
have been stolen if this exploit was committed by attackers. There are not many ways you can
get past the Heartbleed vulnerability because of the program language that OpenSSL uses as it
does not build in any detection mechanisms or countermeasures (Wheeler 2014). The
information found in this study should greatly benefit system administrators and reassure them to
make sure that they patch, reissue, and revoke the certain certificates that could be coming from
attackers seeking to steal information.
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
4
Discussion
The study that was completed by Zhang et al. (2014) contained information and well
thought out methods on how to test different websites certificates and determine if they were
vulnerable to a security bug and showed the importance of the bug which allowed attackers to be
able to read sensitive information that should not be accessible. The study also went into detail
about how a big cause for the certificates to become breached and allow attackers to impersonate
them are from mistakes by the system administrators and their failure to reissue and revoke
certificates allowing important data to be compromised. This ties into businesses because the
chance that attackers could possibly have the chance at viewing personal data from customers
such as people who shop on sites like eBay and Amazon this could lead to a huge data breach
leaving their data with a potential risk of being leaked. The best way to let this attack have
minimal impact is to have your system administrators trained and make sure they do not slack off
and incorrectly reissue certificates and to keep track on countermeasures to combat the
vulnerabilities.
Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed
5
References
Zhang, L., Choffnes, D., Levin, D., Dumitras, T., Mislove, A., Schulman, A., & Wilson, C.
(2014). Analysis of SSL certificate reissues and revocations in the wake of
heartbleed.-Proceedings of the 2014 Conference on Internet Measurement Conference - IMC 14.
doi:10.1145/2663716.2663758
Paterson, K. (2018). On heartbleed: A hard beginnyng makth a good endyng John Heywood
(1497--1580).-Communications of the ACM,61(3), 108-108. doi:10.1145/3176242
Wheeler, D. A. (2014). Preventing Heartbleed.-Computer,47(8), 80-83.
doi:10.1109/mc.2014.217
Powered by TCPDF (www.tcpdf.org)
Students also viewed