Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed.

A properly managed public key infrastructure (PKI) is critical to ensure secure communication on the Internet. Surprisingly, some of the most important administrative steps--in particular, reissuing new X.509 certificates and revoking old ones--are manual and remained unstudied, largely because it i...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 61; no. 3; pp. 109 - 117
Autores principales: Liang Zhang, Choffnes, David, Dumitras, Tudor, Levin, Dave, Mislove, Alan, Schulman, Aaron, Wilson, Christo
Formato: Artículo
Publicado: Association for Computing Machinery Mar2018
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=128238113&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 128238113
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Mar2018
      vid: 61
      iid: 3
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        128238113
        10.1145/3176244
      ppf: 109
      ppct: 8
      formats:
      tig:
        atl: Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed.
      aug:
        au:
          Liang Zhang
          Choffnes, David
          Dumitras, Tudor
          Levin, Dave
          Mislove, Alan
          Schulman, Aaron
          Wilson, Christo
        affil:
          Northeastern University, Boston, MA, USA
          University of Maryland, College Park, MD, USA
          Stanford University, Stanford, CA, USA
      su:
        OpenSSL (Computer software)
        Public key infrastructure (Computer security)
        Digital certificates
        Software upgrades
        Internet servers
        Security systems
      sug:
        subj:
          OpenSSL (Computer software)
          Public key infrastructure (Computer security)
          Digital certificates
          Software upgrades
          Internet servers
          Security systems
      ab: A properly managed public key infrastructure (PKI) is critical to ensure secure communication on the Internet. Surprisingly, some of the most important administrative steps--in particular, reissuing new X.509 certificates and revoking old ones--are manual and remained unstudied, largely because it is difficult to measure these manual processes at scale. We use Heartbleed, a widespread OpenSSL vulnerability from 2014, as a natural experiment to determine whether administrators are properly managing their certificates. All domains affected by Heartbleed should have patched their software, revoked their old (possibly compromised) certificates, and reissued new ones, all as quickly as possible. We find the reality to be far from the ideal: over 73% of vulnerable certificates were not reissued and over 87% were not revoked three weeks after Heartbleed was disclosed. Our results also show a drastic decline in revocations on the weekends, even immediately following the Heartbleed announcement. These results are an important step in understanding the manual processes on which users rely for secure, authenticated communication.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2018
    holdings:
      @attributes:
        islocal: N