The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal con- ditions, by the SSL/TLS encryption [4] used to secure the Internet. SSL/TLS provides com- munication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some Virtual Private Network (VPN) software. The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software library. This bug compromises the secret keys used to identify the service providers and to encrypt the trac, the names and passwords of the users and the actual content. The Heartbleed bug allows attackers to eavesdrop communications, steal data directly from the services and users and to impersonate services and users.

Analysis of the Heartbleed Bug

Enrico Cambiaso;Gianluca Papaleo;Paolo Farina;Maurizio Aiello
2014

Abstract

The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal con- ditions, by the SSL/TLS encryption [4] used to secure the Internet. SSL/TLS provides com- munication security and privacy over the Internet for applications such as web, email, instant messaging (IM) and some Virtual Private Network (VPN) software. The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software library. This bug compromises the secret keys used to identify the service providers and to encrypt the trac, the names and passwords of the users and the actual content. The Heartbleed bug allows attackers to eavesdrop communications, steal data directly from the services and users and to impersonate services and users.
2014
Istituto di Elettronica e di Ingegneria dell'Informazione e delle Telecomunicazioni - IEIIT
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.14243/249764
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus ND
  • ???jsp.display-item.citation.isi??? ND
social impact