Skip to main navigation Skip to search Skip to main content

Empirical analysis of SSL/TLS weaknesses in real websites: Who cares?

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

As SSL/TLS has become the de facto standard Internet protocol for secure communication in recent years, its security issues have also been intensively studied. Even though several tools have been introduced to help administrators know which SSL/TLS vulnerabilities exist in their network hosts, it is still unclear whether the best security practices are effectively adopted to fix those vulnerabilities in real-world applications. In this paper, we present the landscape of real websites about SSL/TLS weaknesses through an automatic analysis of the possibilities of six representative SSL/TLS attacks—Heartbleed, POODLE, CCS injection, FREAK, Logjam and DROWN—on popular websites. Surprisingly, our experiments show that 45% and 52.6% of top 500 most popular global and Korean websites are still vulnerable to at least one of those attacks, respectively. We also observed several interesting trends in how websites were vulnerable to those attacks. Our findings suggest that better tools and education programs for SSL/TLS security are needed to help administrators keep their systems up-to-date with security patches.

Original languageEnglish
Title of host publicationInformation Security Applications - 17th International Workshop, WISA 2016, Revised Selected Papers
EditorsDooho Choi, Sylvain Guilley
PublisherSpringer Verlag
Pages174-185
Number of pages12
ISBN (Print)9783319565484
DOIs
StatePublished - 2017
Event17th International Workshop on Information Security Applications, WISA 2016 - Jeju Island, Korea, Republic of
Duration: 25 Aug 201625 Aug 2016

Publication series

NameLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volume10144 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference17th International Workshop on Information Security Applications, WISA 2016
Country/TerritoryKorea, Republic of
City Jeju Island
Period25/08/1625/08/16

Keywords

  • Attack
  • Security patch
  • SSL/TLS
  • Vulnerability

Fingerprint

Dive into the research topics of 'Empirical analysis of SSL/TLS weaknesses in real websites: Who cares?'. Together they form a unique fingerprint.

Cite this