Skip to main navigation Skip to search Skip to main content

Assessment of the impacts of TLS vulnerabilities in the HTTPS ecosystem of China

  • J. K. Huang
  • , Z. X. Zhang*
  • , W. J. Li
  • , Y. Xin
  • *Corresponding author for this work
  • Harbin Institute of Technology
  • Police Support Branch of Changping District Bureau of Beijing Public Security Bureau

Research output: Contribution to journalConference articlepeer-review

Abstract

In order to assess the regional impacts of TLS vulnerabilities in China, by using the combination of CT logs and IPv4 scans, we made measurements of the HTTPS ecosystem of China and obtained a representative dataset. Based on the dataset, we analyzed the impacts of TLS vulnerabilities on China, including Heartbleed, Logjam and the use of weak hash algorithms. Then we represented the results of the impacts of these vulnerabilities. Our studies showed the severity of these vulnerabilities in China has been controlled at a low level, except the attacks on outdated hash algorithms like SHA1 that is proved to be not secure recently, which affect over 33% of available HTTPS servers in China. And we found the impacts of these vulnerabilities are concentrated in where information industry is developed relatively. Lastly, we concluded with the lag situation of HTTPS ecosystem of China needed to solve urgently in the development of Internet security.

Original languageEnglish
Pages (from-to)512-518
Number of pages7
JournalProcedia Computer Science
Volume147
DOIs
StatePublished - 2019
Event7th International Conference on Identification, Information and Knowledge in the Internet of Things, IIKI 2018 - Beijing, China
Duration: 19 Oct 201821 Oct 2018

Keywords

  • HTTPS
  • Internet-wide scanning
  • TLS
  • security
  • vulnerabilities

Fingerprint

Dive into the research topics of 'Assessment of the impacts of TLS vulnerabilities in the HTTPS ecosystem of China'. Together they form a unique fingerprint.

Cite this