The matter of heartbleed

Z Durumeric, F Li, J Kasten, J Amann… - Proceedings of the …, 2014 - dl.acm.org
Proceedings of the 2014 conference on internet measurement conference, 2014dl.acm.org
The Heartbleed vulnerability took the Internet by surprise in April 2014. The vulnerability,
one of the most consequential since the advent of the commercial Internet, allowed attackers
to remotely read protected memory from an estimated 24--55% of popular HTTPS sites. In
this work, we perform a comprehensive, measurement-based analysis of the vulnerability's
impact, including (1) tracking the vulnerable population,(2) monitoring patching behavior
over time,(3) assessing the impact on the HTTPS certificate ecosystem, and (4) exposing …
The Heartbleed vulnerability took the Internet by surprise in April 2014. The vulnerability, one of the most consequential since the advent of the commercial Internet, allowed attackers to remotely read protected memory from an estimated 24--55% of popular HTTPS sites. In this work, we perform a comprehensive, measurement-based analysis of the vulnerability's impact, including (1) tracking the vulnerable population, (2) monitoring patching behavior over time, (3) assessing the impact on the HTTPS certificate ecosystem, and (4) exposing real attacks that attempted to exploit the bug. Furthermore, we conduct a large-scale vulnerability notification experiment involving 150,000 hosts and observe a nearly 50% increase in patching by notified hosts. Drawing upon these analyses, we discuss what went well and what went poorly, in an effort to understand how the technical community can respond more effectively to such events in the future.
ACM Digital Library