Assessment of the impacts of TLS vulnerabilities in the HTTPS ecosystem of China
Jiajun Huang, Zhibin Zhang, Wenhao Li, Yi Xin · Procedia Computer Science · 2019
In order to assess the regional impacts of TLS vulnerabilities in China, by using the combination of CT logs and IPv4 scans, we made measurements of the HTTPS ecosystem of China and obtained a representative dataset. Based on the dataset, we analyzed the impacts of TLS vulnerabilities on China, including Heartbleed, Logjam and the use of weak hash algorithms. Then we represented the results of the impacts of these vulnerabilities. Our studies showed the severity of these vulnerabilities in China has been controlled at a low level, except the attacks on outdated hash algorithms like SHA1 that is proved to be not secure recently, which affect over 33% of available HTTPS servers in China. And we found the impacts of these vulnerabilities are concentrated in where information industry is developed relatively. Lastly, we concluded with the lag situation of HTTPS ecosystem of China needed to solve urgently in the development of Internet security.