Sokoine University of Agriculture

Using soft systems methodology and activity theory to exploit security of web applications against heartbleed vulnerability

Show simple item record

dc.contributor.author Mshangi, Maduhu
dc.contributor.author Nfuka, Edephonce Ngemera
dc.contributor.author Sanga, Camilius
dc.date.accessioned 2017-01-19T16:39:54Z
dc.date.available 2017-01-19T16:39:54Z
dc.date.issued 2015
dc.identifier.uri https://www.suaire.sua.ac.tz/handle/123456789/1183
dc.description International Journal of Computing and ICT Research, Vol. 8, Issue 2, June 2015 en_US
dc.description.abstract The number of security incidents exploiting security holes in the web applications is increasing. One of the recently identified vulnerability in the web applications is the Heartbleed bug. The Heartbleed bug is a weakness found in OpenSSL, open source cryptographic software. In this study, both quantitative and qualitative research methodologies were employed. Case study and content/documentary analysis research methods were used to collect data for probing the web applications which are vulnerable to the bug. Due to the complexity of the problem, Soft Systems Methodology was adopted for the management of the analysis of data. The evaluation of security of web applications involved 64 selected websites of higher education institutions in Africa. SSM was supported by a theory called Activity Theory. The collected data was analysed using “R statistical computing package”. The study found that 89% of the universities web applications in Africa were vulnerable to the Heartbleed attack; and 11% of the universities web applications in Africa were not vulnerable to Heartbleed on the public announcement of the bug. But about two months later after the public announcement of the bug, 16% of the most universities web applications which were vulnerable were patched for the Heartbleed bug. The study seeks to contribute in application of Soft Systems Methodology and Activity Theory in the body of knowledge of information systems security (ISS). en_US
dc.language.iso en en_US
dc.publisher International Journal of Computing and ICT Research, en_US
dc.relation.ispartofseries International Journal of Computing and ICT Research,;Vol. 8, Issue 2, June 2015
dc.subject Computing Management en_US
dc.subject Heartbleed bug en_US
dc.subject Web application en_US
dc.subject System security en_US
dc.subject Activity theory en_US
dc.subject Information systems security (ISS) en_US
dc.title Using soft systems methodology and activity theory to exploit security of web applications against heartbleed vulnerability en_US
dc.type Article en_US
dc.url http://ijcir.mak.ac.ug/volume8-issue2/article4.pdf en_US


Files in this item

This item appears in the following Collection(s)

Show simple item record

Search SUA IR


Browse

My Account

Statistics