Pith. sign in

REVIEW 3 cited by

The Race to the Vulnerable: Measuring the Log4j Shell Incident

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2205.02544 v2 pith:F7VNMD62 submitted 2022-05-05 cs.CR

classification cs.CR
keywords scannersdisclosurelibrarylog4jmaliciousrushvulnerabilityvulnerable
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The critical remote-code-execution (RCE) Log4Shell is a severe vulnerability that was disclosed to the public on December 10, 2021. It exploits a bug in the wide-spread Log4j library. Any service that uses the library and exposes an interface to the Internet is potentially vulnerable. In this paper, we measure the rush of scanners during the two months after the disclosure. We use several vantage points to observe both researchers and attackers. For this purpose, we collect and analyze payloads sent by benign and malicious communication parties, their origins, and churn. We find that the initial rush of scanners quickly ebbed. Especially non-malicious scanners were only interested in the days after the disclosure. In contrast, malicious scanners continue targeting the vulnerability.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. WildCode Revisited: A Comprehensive Empirical Study on the Security of LLM-Generated Code

    cs.CR 2025-12 conditional novelty 6.0 of 10

    Using real ChatGPT conversation logs, code generated by the model is frequently insecure and users rarely request security-related code.

  2. Beyond Window-Based Detection: A Graph-Centric Framework for Discrete Log Anomaly Detection

    cs.SE 2025-01 conditional novelty 6.0 of 10

    TempoLog replaces fixed-size log windows with continuous-time dynamic graphs and link prediction to detect anomalies at individual event level.

  3. TrustZero -- open, verifiable and scalable zero-trust

    cs.CR 2025-02 reject novelty 3.0 of 10

    TrustZero proposes a trust token made of server signatures and a trust score that counts them, with a proof-of-concept, but the score is defined so that valid signatures are the same as trust.

Pith tools