REVIEW 3 cited by
The Race to the Vulnerable: Measuring the Log4j Shell Incident
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
The critical remote-code-execution (RCE) Log4Shell is a severe vulnerability that was disclosed to the public on December 10, 2021. It exploits a bug in the wide-spread Log4j library. Any service that uses the library and exposes an interface to the Internet is potentially vulnerable. In this paper, we measure the rush of scanners during the two months after the disclosure. We use several vantage points to observe both researchers and attackers. For this purpose, we collect and analyze payloads sent by benign and malicious communication parties, their origins, and churn. We find that the initial rush of scanners quickly ebbed. Especially non-malicious scanners were only interested in the days after the disclosure. In contrast, malicious scanners continue targeting the vulnerability.
Forward citations
Cited by 3 Pith papers
-
WildCode Revisited: A Comprehensive Empirical Study on the Security of LLM-Generated Code
Using real ChatGPT conversation logs, code generated by the model is frequently insecure and users rarely request security-related code.
-
Beyond Window-Based Detection: A Graph-Centric Framework for Discrete Log Anomaly Detection
TempoLog replaces fixed-size log windows with continuous-time dynamic graphs and link prediction to detect anomalies at individual event level.
-
TrustZero -- open, verifiable and scalable zero-trust
TrustZero proposes a trust token made of server signatures and a trust score that counts them, with a proof-of-concept, but the score is defined so that valid signatures are the same as trust.
Discussion (0). Continue with ORCID to comment.