Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed.
A properly managed public key infrastructure (PKI) is critical to ensure secure communication on the Internet. Surprisingly, some of the most important administrative steps--in particular, reissuing new X.509 certificates and revoking old ones--are manual and remained unstudied, largely because it i...
| Publicado en: | Communications of the ACM Vol. 61; no. 3; pp. 109 - 117 |
|---|---|
| Autores principales: | , , , , , , |
| Formato: | Artículo |
| Publicado: |
Association for Computing Machinery
Mar2018
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=128238113&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 128238113 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 00010782 ACM jtl: Communications of the ACM issn: 00010782 maglogo: N pubinfo: dt: Mar2018 vid: 61 iid: 3 pid: 68 pub: Association for Computing Machinery artinfo: ui: 128238113 10.1145/3176244 ppf: 109 ppct: 8 formats: tig: atl: Analysis of SSL Certificate Reissues and Revocations in the Wake of Heartbleed. aug: au: Liang Zhang Choffnes, David Dumitras, Tudor Levin, Dave Mislove, Alan Schulman, Aaron Wilson, Christo affil: Northeastern University, Boston, MA, USA University of Maryland, College Park, MD, USA Stanford University, Stanford, CA, USA su: OpenSSL (Computer software) Public key infrastructure (Computer security) Digital certificates Software upgrades Internet servers Security systems sug: subj: OpenSSL (Computer software) Public key infrastructure (Computer security) Digital certificates Software upgrades Internet servers Security systems ab: A properly managed public key infrastructure (PKI) is critical to ensure secure communication on the Internet. Surprisingly, some of the most important administrative steps--in particular, reissuing new X.509 certificates and revoking old ones--are manual and remained unstudied, largely because it is difficult to measure these manual processes at scale. We use Heartbleed, a widespread OpenSSL vulnerability from 2014, as a natural experiment to determine whether administrators are properly managing their certificates. All domains affected by Heartbleed should have patched their software, revoked their old (possibly compromised) certificates, and reissued new ones, all as quickly as possible. We find the reality to be far from the ideal: over 73% of vulnerable certificates were not reissued and over 87% were not revoked three weeks after Heartbleed was disclosed. Our results also show a drastic decline in revocations on the weekends, even immediately following the Heartbleed announcement. These results are an important step in understanding the manual processes on which users rely for secure, authenticated communication. pubtype: Periodical doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2018 holdings: @attributes: islocal: N |
|---|