The Race to the Vulnerable: Measuring the Log4j Shell Incident

The Race to the Vulnerable: Measuring the Log4j Shell Incident
复制标题

DOI:
10.48550/arxiv.2205.02544
复制
发表时间:
2022-05
期刊:
ArXiv
影响因子:
--
通讯作者:
Raphael Hiesgen;Marcin Nawrocki;T. Schmidt;Matthias Wählisch
Raphael Hiesgen;Marcin Nawrocki;T. Schmidt;Matthias Wählisch
中科院分区:
其他
文献类型:
--
作者:
Raphael Hiesgen;Marcin Nawrocki;T. Schmidt;Matthias Wählisch

文献摘要

被引文献

相似文献

关键远程代码执行 (RCE) Log4Shell 是一个严重漏洞,于 2021 年 12 月 10 日向公众披露。它利用了广泛传播的 Log4j 库中的一个错误。任何使用该库并向 Internet 公开接口的服务都可能容易受到攻击。在本文中,我们测量了信息披露后两个月内扫描仪的激增情况。我们使用多个有利位置来观察研究人员和攻击者。为此,我们收集并分析良性和恶意通信方发送的有效负载、其来源和流失情况。我们发现最初的扫描仪热潮很快就消退了。特别是非恶意扫描器只对披露后的几天感兴趣。相反,恶意扫描程序继续针对该漏洞。
The critical remote-code-execution (RCE) Log4Shell is a severe vulnerability that was disclosed to the public on December 10, 2021. It exploits a bug in the wide-spread Log4j library. Any service that uses the library and exposes an interface to the Internet is potentially vulnerable. In this paper, we measure the rush of scanners during the two months after the disclosure. We use several vantage points to observe both researchers and attackers. For this purpose, we collect and analyze payloads sent by benign and malicious communication parties, their origins, and churn. We find that the initial rush of scanners quickly ebbed. Especially non-malicious scanners were only interested in the days after the disclosure. In contrast, malicious scanners continue targeting the vulnerability.