Cybersecurity experts reveal U.S. admins' flaws in fixing Heartbleed bug

Image
ANI Washington
Last Updated : Nov 09 2014 | 4:25 PM IST

Cybersecurity experts from a university conducted a detailed analysis and found that website administrators nationwide tasked with patching security holes exploited by the Heartbleed bug might not have done enough.

The Heartbleed bug, which was first disclosed in April this year, presents a serious vulnerability to the popular OpenSSL (Secure Sockets Layer) software, allowing anyone on the Internet to read the memory of systems that are compromised by the malicious bug.

A team of cybersecurity experts from the University of Maryland analyzed the most popular websites in the United States, more than one million sites were examined, to better understand the extent to which systems administrators followed specific protocols to fix the problem.

Assistant Research Scientist Dave Levin and Assistant Professor of Electrical and Computer Engineering Tudor Dumitras team, which included researchers from Northeastern University and Stanford University, discovered that while approximately 93 percent of the websites analyzed had patched their software correctly within three weeks of Heartbleed being announced, only 13 percent followed up with other security measures needed to make the systems completely secure.

Levin said that once Heartbleed was made public website administrators everywhere should have immediately taken three steps to regain better control and security over their systems.

He revealed that they needed to patch their OpenSSL software, they needed to revoke their current certificates, and they needed to reissue new ones.

The team's data analysis also highlighted an interesting trend that points to the role that humans play in these complex security systems, said Dumitras. In a graph displaying how many certifications were revoked over the course of the three weeks, their data shows a significant drop in revocation rates during weekends.

Dumitras and Levin hope that the team's findings would spur conversations regarding the multiple factors that influence overall computer security, and how those factors can work together to better strengthen systems.

Levin said that security isn't something to be taken for granted, adding that he sees some of these results and is shocked and surprised and a little bit scared. But he said that at the same time, he sees it as opportunity for improvement.

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Nov 09 2014 | 4:13 PM IST

Next Story