Using soft systems methodology and activity theory to exploit security of web applications against heartbleed vulnerability

dc.contributor.authorMshangi, Maduhu
dc.contributor.authorNfuka, Edephonce Ngemera
dc.contributor.authorSanga, Camilius
dc.date.accessioned2017-01-19T16:39:54Z
dc.date.available2017-01-19T16:39:54Z
dc.date.issued2015
dc.descriptionInternational Journal of Computing and ICT Research, Vol. 8, Issue 2, June 2015en_US
dc.description.abstractThe number of security incidents exploiting security holes in the web applications is increasing. One of the recently identified vulnerability in the web applications is the Heartbleed bug. The Heartbleed bug is a weakness found in OpenSSL, open source cryptographic software. In this study, both quantitative and qualitative research methodologies were employed. Case study and content/documentary analysis research methods were used to collect data for probing the web applications which are vulnerable to the bug. Due to the complexity of the problem, Soft Systems Methodology was adopted for the management of the analysis of data. The evaluation of security of web applications involved 64 selected websites of higher education institutions in Africa. SSM was supported by a theory called Activity Theory. The collected data was analysed using “R statistical computing package”. The study found that 89% of the universities web applications in Africa were vulnerable to the Heartbleed attack; and 11% of the universities web applications in Africa were not vulnerable to Heartbleed on the public announcement of the bug. But about two months later after the public announcement of the bug, 16% of the most universities web applications which were vulnerable were patched for the Heartbleed bug. The study seeks to contribute in application of Soft Systems Methodology and Activity Theory in the body of knowledge of information systems security (ISS).en_US
dc.identifier.urihttps://www.suaire.sua.ac.tz/handle/123456789/1183
dc.language.isoenen_US
dc.publisherInternational Journal of Computing and ICT Research,en_US
dc.relation.ispartofseriesInternational Journal of Computing and ICT Research,;Vol. 8, Issue 2, June 2015
dc.subjectComputing Managementen_US
dc.subjectHeartbleed bugen_US
dc.subjectWeb applicationen_US
dc.subjectSystem securityen_US
dc.subjectActivity theoryen_US
dc.subjectInformation systems security (ISS)en_US
dc.titleUsing soft systems methodology and activity theory to exploit security of web applications against heartbleed vulnerabilityen_US
dc.typeArticleen_US
dc.urlhttp://ijcir.mak.ac.ug/volume8-issue2/article4.pdfen_US

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
Camilius Sanga.pdf
Size:
408.79 KB
Format:
Adobe Portable Document Format

License bundle

Now showing 1 - 1 of 1
No Thumbnail Available
Name:
license.txt
Size:
1.66 KB
Format:
Item-specific license agreed upon to submission
Description: