11
Zulfikar Ramzan, PhD, MIT Chief Technology Officer Elastica The Heartbleed Bug

The Heartbleed Bug

Embed Size (px)

DESCRIPTION

Heartbleed is a newly discovered very widespread vulnerability in the OpenSSL implementation of the SSL/TLS protocol. The flaw allows attackers to steal passwords and confidential data that you have provided online. Elastica’s CTO Dr. Zulfikar Ramzan walks through the flaw’s mechanics and ramifications.

Citation preview

Page 1: The Heartbleed Bug

Zulfikar Ramzan, PhD, MITChief Technology OfficerElastica

The Heartbleed Bug

Page 2: The Heartbleed Bug

Massive OpenSSL Bug 'Heartbleed'

Threatens Sensitive Data

- Wall S

treet Journal

OpenSSL Heartbleed Bug Leaves Much Of The Internet At Risk

- TechCrunch

Experts Find a Door Ajar in an

Internet Security Method Thought

Safe

- The New York Times

Page 3: The Heartbleed Bug

On 07 April 2014, security experts disclosed that a serious vulnerability had been identified in OpenSSL cryptographic

software library that protects many web sites. 

This problem might have been there for almost 2 years, but just hidden in plain

sight..

Page 4: The Heartbleed Bug

When you transact online, your information is protected by the SSL/TLS encryption used to secure the Internet.

OpenSSL is an open-source implementation of the SSL protocol.

The Heartbeat protocol is a sub-part of SSL and is meant to ensure communications are kept alive.

Page 5: The Heartbleed Bug

The Heartbleed bug is a devastating vulnerability in the heartbeat extension of the SSL/TLS protocol (CVE-2014-0160).

It specifically impacts version 1.0.1 and beta versions of 1.0.2 of OpenSSL.

It compromises encryption keys, user credentials and actual content.

Page 6: The Heartbleed Bug

The Heartbleed bug allows attackers to

• eavesdrop on communications online

• get access to sensitive data such as passwords, social security numbers, financial records, etc

• impersonate users and services

• and, all this can be done multiple times and without a trace!

Page 8: The Heartbleed Bug

Up to two-thirds of

websites use OpenSSL

and could be vulnerable.

List of possibly affected sites

Tool to test a website

Page 9: The Heartbleed Bug

What should you do?

Check if your favorite sites have implemented the Heartbleed patch.

If it has been patched, then log in and change your password.

If you change your password and the site hasn’t been patched, then you’re giving a hacker a new password.

Page 10: The Heartbleed Bug

When password compromises happen, new machine learning based methods are needed to find the breaches and anomalies.

Elastica’s Detect App on CloudSOC uses behavioral analysis to zero-in on threats to your assets in the cloud and gives you protection beyond simple username/password.

Is there an alternative? LEARN MORE

Page 11: The Heartbleed Bug

Thank you.