Menu
Study concludes 'Heartbleed' flaw was unknown before disclosure

Study concludes 'Heartbleed' flaw was unknown before disclosure

Network traffic records show no signs attackers were looking for vulnerable servers before Heartbleed's disclosure

One of the most serious software flaws to affect the Internet, nicknamed "Heartbleed," was likely unknown before it was publicly disclosed, according to new research.

The finding puts to rest fears that government spying agencies may have been exploiting the flaw for surveillance activities.

Widespread attacks using Heartbleed only began about a day after information about it became public, according to the paper, published by researchers at several U.S. universities.

"We find no evidence of exploitation prior to the vulnerability's public disclosure, but we detect subsequent exploit attempts from almost 700 sources beginning less than 24 hours after disclosure," they wrote.

Heartbleed was a flaw in older versions of OpenSSL, a widely used cryptographic library that encrypts data traffic between a client and a server. In some cases, Heartbleed leaked memory from a server, potentially exposing login credentials, cryptographic keys and other private data.

Its disclosure on April 7 set off a scramble to patch. Upwards of 55 percent of the top one million websites ranked by traffic by Alexa were affected, many of which were quickly patched.

To figure out if attacks had been executed against OpenSSL prior to disclosure of the flaw, the researchers analyzed network traffic collected by passive traps at Lawrence Berkeley National Laboratory, the National Energy Research Scientific Computing Center and a honeypot on Amazon's EC2 network.

The networks collectively had full packet traces available from around November 2013 through April. No tell-tale signs that attackers were trying to exploit Heartbleed were found, although such scanning for vulnerable servers "could have occurred during other time periods," they cautioned.

The first attacks were detected 21 hours and 29 minutes after Heartbleed became public from a host at the University of Latvia, they wrote. Soon after, the attacks came fast and furious.

Two days after Heartbleed was disclosed, about 11 percent of the top 1 million sites ranked by Alexa were still vulnerable. The top 500 sites, however, had all patched within that same period.

Three weeks after disclosure, the researchers began contacting the operators of more than 200,000 hosts that were still vulnerable, a laborious undertaking. They did that by extracting the "abuse" email contacts from Whois records.

"When we notified network operators of the unpatched systems in their address space, the rate of patching increased by 47 percent," the paper read. "Many of the operators reported they had intended to patch, but that they had missed the system we detected."

The success of that effort challenges the belief that mass notifications of vulnerabilities would be ineffective or too difficult, they wrote.

"Future work is needed to understand what factor influence the effectiveness of mass notifications and determine how best to perform them," they wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


Follow Us

Join the newsletter!

Error: Please check your email address.

Tags no companysecurity

Featured

Slideshows

Tech industry comes together as Lexel celebrates turning 30

Tech industry comes together as Lexel celebrates turning 30

Leading figures within the technology industry across New Zealand came together to celebrate 30 years of success for Lexel Systems, at a milestone birthday occasion at St Matthews in the City.​

Tech industry comes together as Lexel celebrates turning 30
HP re-imagines education through Auckland event launch

HP re-imagines education through Auckland event launch

HP New Zealand held an inaugural Evolve Education event at Aotea Centre in Auckland, welcoming over 70 principals, teachers and education experts to explore ways of shaping and enhancing learning using technology.

HP re-imagines education through Auckland event launch
Reseller News ICT Industry Awards 2017 - Meet the winners...

Reseller News ICT Industry Awards 2017 - Meet the winners...

Reseller News honoured the industry’s finest on a standout evening for the New Zealand channel, recognising the achievements of established and emerging partners on a memorable night in Auckland.

Reseller News ICT Industry Awards 2017 - Meet the winners...
Show Comments