Study on OpenSSL Heartbleed Attack Principle and Defense Method

Si-hua AN,Ping YI,Xin-chun WANG,Chao-feng LI
DOI: https://doi.org/10.3969/j.issn.1002-0802.2014.07.018
2014-01-01
Abstract:OpenSSL is an open source code library of secure sockets layer. It is accomplished with C. It a-chieves the basic function of transport layer data encryption. OpenSSL is widely used in major online bank-ing, online payment, electricity supplier sites, portal website, email, and other fields. So OpenSSL's safety and reliability are very import. Since OpenSSL's vulnerabilities may lead to a large network disaster, it is necessary to study its vulnerability. The article introduces the newly discovered loophole named OpenSSL Heartbleed, analyzes the attack principle and introduces some methods to defense this attack. First it proposes the concept of OpenSSL, then analyzes the attack principle of Heartbleed, at last intro-duces some methods to prevention this attack.
What problem does this paper attempt to address?