Question: Question 1 Heartbleed is a major security bug in OpenSSL, which is a software library for applications that secure communications over computer networks. This vulnerability

Question 1
Heartbleed is a major security bug in OpenSSL, which is a software library for applications that secure communications over computer networks. This vulnerability was discovered in 2014, and it affected a large number of websites, software applications, and operating systems. In this vulnerability, the library does not perform proper input validation and hence it allows attackers to craft special requests that reveal more memory contents than allowed, such as the servers private key, the users sensitive requests and responses, including session cookies and passwords. Hackers could exploit this vulnerability to attack intercepted past and future communications.
Which security goal (Availability/Integrity/Confidentiality) was primarily affected by Heartbleed vulnerability? Explain your reasoning.
A data server has been found to have the Heartbleed vulnerability. Suggest one (1) technical preventive control and one (1) administrative preventive control to ensure the security of the server and its users against Heartbleed-based attacks and briefly explain how they address the problem.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!