Using MIS (9th Edition)
Using MIS (9th Edition)
9th Edition
ISBN: 9780134106786
Author: David M. Kroenke, Randall J. Boyle
Publisher: PEARSON
Expert Solution & Answer
Book Icon
Chapter 4.8, Problem 4SGDQ

Explanation of Solution

Reason for the portion of “OpenSSL” code containing the Heartbleed vulnerability:

  • Based on the given it is said that the portion of open SSL (Secure sockets Layer) code contains errors because of the shortage in paid code checkers.
  • Open SSL is an open source project involving the small team or community who releases code for free whenever it is required.

Heartbeat:

  • Consider a client accessing a secure server.
  • A client shares a particular amount of random number to its server.
  • The server will in turn make copies of those random data and will send the data again to the client.
  • This type of action is called as heartbeat which ensures both client and server are present in an active state.
  • This action happens in the “TLS” (transport Layer Security) which ensures the protection of confidential data that being searched on the web.
  • It will have its connection remained opened even if no data are being shared.
  • This operation will have smooth process until an error or fault that it contains in the Open SSL.

Heartbleed:

  • When an error occurs in the code of open source open SSL (Secure Socket Layer) cryptographic library “Heartbleed” vulnerability occurs.
    • Error that could occur is, consider if the user or client intimates to send a particular amount of information but delivers only a few amount of information that it had intimated, the act of sending less amount of information than it committed to the server is the error, in this case the server in turn replies to the client by sending the information in the amount the client as intimated...

Blurred answer
Knowledge Booster
Background pattern image
Recommended textbooks for you
Text book image
Database System Concepts
Computer Science
ISBN:9780078022159
Author:Abraham Silberschatz Professor, Henry F. Korth, S. Sudarshan
Publisher:McGraw-Hill Education
Text book image
Starting Out with Python (4th Edition)
Computer Science
ISBN:9780134444321
Author:Tony Gaddis
Publisher:PEARSON
Text book image
Digital Fundamentals (11th Edition)
Computer Science
ISBN:9780132737968
Author:Thomas L. Floyd
Publisher:PEARSON
Text book image
C How to Program (8th Edition)
Computer Science
ISBN:9780133976892
Author:Paul J. Deitel, Harvey Deitel
Publisher:PEARSON
Text book image
Database Systems: Design, Implementation, & Manag...
Computer Science
ISBN:9781337627900
Author:Carlos Coronel, Steven Morris
Publisher:Cengage Learning
Text book image
Programmable Logic Controllers
Computer Science
ISBN:9780073373843
Author:Frank D. Petruzella
Publisher:McGraw-Hill Education