Vulnerabilities / Threats
6/2/2014
11:41 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

SSL: Security's Best Friend Or Worst Enemy?

A new report shows that applications using SSL are on the rise in enterprises, putting them at greater risk of attacks that hide in plain sight or use vulnerabilities like Heartbleed.

A new report out today shows that applications that use SSL are on the rise in the enterprise, and that even businesses that are aware of the risks introduced by SSL aren't necessarily aware of the scale of potential problems.

The findings from the 11th annual Palo Alto Networks Application Usage and Threat Report show that around 34% of applications in use within the enterprise today use or can use the SSL to encrypt their traffic. Designed to survey the real applications running in the enterprise, it also shows the disparity between enterprise IT leaders' perception of their use of applications and the actual usage patterns or properties of applications scattered across organization. This year, the report studied 5,500 real-world environments and found approximately 2,100 applications running within these environments. Among those, 539 were SSL-capable.

As one of the core components of today's Internet ecosystem, SSL has greased the axle of Internet communication for key transactions like e-commerce and collaborative sharing applications, says Ryan Olson, head of threat intelligence for Palo Alto.

"Without having a sort of ubiquitous encryption protocol that is easy for people to implement, we wouldn't really be able to have any secure communication across the Internet," Olson says. However, the heightened level of privacy afforded by SSL encryption also brings with it a dark side.

"We certainly have a trade-off from a network perspective," he says, explaining that attackers increasingly use SSL to hide malicious traffic in plain sight from security inspection mechanisms. For example, he explains that variants of Zeus and other banking Trojans use SSL to hide command and control traffic from security devices. Similarly, the report pointed to the variant of the BlackPOS Trojan used to steal 100 million Target customer records, which used SSL to move information around using netbios shares and steal it through FTP.

"A lot of organizations are aware of this problem, but not as many as we think should be," he says. "The best way to deal with SSL is to do selective decryption of SSL traffic. We don't want to decrypt everything -- it's not really appropriate, and you don't want to invade the privacy of users in an inappropriate way. But many organizations don't do this for any applications at all. For applications which you have no idea what they are, you definitely want to have some visibility into what they are."

This is not a new problem, but it is a growing one as the number of SSL-capable applications rises within the enterprise. According to Palo Alto, the ratio grew by nearly 10 percentage points in the past year.

"I definitely don't see this decreasing over time, and it becomes even more difficult for organization as the total volume of SSL traffic increases. If you have a slice of your overall traffic you're ignoring because you're not inspecting it, as that slice grows larger the percentage of traffic that's going to include malicious behavior is going to increase proportionally," Olson says. 

Further increasing the threat is what Olson calls the long-term risks of Heartbleed, which are unknown and unpatched client-side applications vulnerable to the OpenSSL Heartbleed vulnerability. As he explains, many websites have gone through the proper stages of patching the vulnerability, reissuing certificates, and asking their users to reset their passwords. But there exists a whole world of client-side applications that organizations might not even know exist in their networks that could still be vulnerable to Heartbleed.

"Instant message application and any client-side application that could include some sort of browser in it might include OpenSSL," he says, "And it might be one of those 500-plus applications in the enterprises that can use SSL."

Palo Alto reported that "a lot of eyebrows were raised" as customers looked at the report's results. In many specific enterprise instances, the percentage of SSL-capable applications running in environments was much higher than 30%, sometimes pushing above 50% of applications in use.

"So, identifying all the applications in your network that are using SSL and figuring out if they use Open SSL is really the long tail of Heartbleed," Olson warns.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Oldest First  |  Newest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.