Menu
Study concludes 'Heartbleed' flaw was unknown before disclosure

Study concludes 'Heartbleed' flaw was unknown before disclosure

Network traffic records show no signs attackers were looking for vulnerable servers before Heartbleed's disclosure

One of the most serious software flaws to affect the Internet, nicknamed "Heartbleed," was likely unknown before it was publicly disclosed, according to new research.

The finding puts to rest fears that government spying agencies may have been exploiting the flaw for surveillance activities.

Widespread attacks using Heartbleed only began about a day after information about it became public, according to the paper, published by researchers at several U.S. universities.

"We find no evidence of exploitation prior to the vulnerability's public disclosure, but we detect subsequent exploit attempts from almost 700 sources beginning less than 24 hours after disclosure," they wrote.

Heartbleed was a flaw in older versions of OpenSSL, a widely used cryptographic library that encrypts data traffic between a client and a server. In some cases, Heartbleed leaked memory from a server, potentially exposing login credentials, cryptographic keys and other private data.

Its disclosure on April 7 set off a scramble to patch. Upwards of 55 percent of the top one million websites ranked by traffic by Alexa were affected, many of which were quickly patched.

To figure out if attacks had been executed against OpenSSL prior to disclosure of the flaw, the researchers analyzed network traffic collected by passive traps at Lawrence Berkeley National Laboratory, the National Energy Research Scientific Computing Center and a honeypot on Amazon's EC2 network.

The networks collectively had full packet traces available from around November 2013 through April. No tell-tale signs that attackers were trying to exploit Heartbleed were found, although such scanning for vulnerable servers "could have occurred during other time periods," they cautioned.

The first attacks were detected 21 hours and 29 minutes after Heartbleed became public from a host at the University of Latvia, they wrote. Soon after, the attacks came fast and furious.

Two days after Heartbleed was disclosed, about 11 percent of the top 1 million sites ranked by Alexa were still vulnerable. The top 500 sites, however, had all patched within that same period.

Three weeks after disclosure, the researchers began contacting the operators of more than 200,000 hosts that were still vulnerable, a laborious undertaking. They did that by extracting the "abuse" email contacts from Whois records.

"When we notified network operators of the unpatched systems in their address space, the rate of patching increased by 47 percent," the paper read. "Many of the operators reported they had intended to patch, but that they had missed the system we detected."

The success of that effort challenges the belief that mass notifications of vulnerabilities would be ineffective or too difficult, they wrote.

"Future work is needed to understand what factor influence the effectiveness of mass notifications and determine how best to perform them," they wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags no companysecurity

Slideshows

Top 50 defining moments of the New Zealand channel in 2016

Top 50 defining moments of the New Zealand channel in 2016

Reseller News looks back on a tumultuous 12 months for the New Zealand channel, assessing the fallout from a year of sizeable industry change. Whether it be local or global mergers and acquisitions, distribution deals or job changes, the channel that started the year differs somewhat to the one set to finish it - Reseller News assesses the key moments that made 2016.​

Top 50 defining moments of the New Zealand channel in 2016
​Hewlett Packard Enterprise honours high achieving NZ channel

​Hewlett Packard Enterprise honours high achieving NZ channel

Hewlett Packard Enterprise honoured its top performing Kiwi partners at the second running of its HPE Partner Awards in New Zealand, held at a glitzy ceremony in Auckland. Recognising excellence across eight categories - from distributors to resellers - the tech giant celebrated its first year as a standalone company, following its official split from HP in 2015.

​Hewlett Packard Enterprise honours high achieving NZ channel
Nutanix treats channel partners to Christmas cruise

Nutanix treats channel partners to Christmas cruise

Nutanix recently took to the seas for a Christmas Cruise around Sydney Harbour with its Australia and New Zealand staff, customers and partners to celebrate a stellar year for the vendor. With the sun out, they were all smiles and mingled over drinks and food.

Nutanix treats channel partners to Christmas cruise
Show Comments