Log4jPot: Effective Log4Shell Vulnerability Detection System

Research output: Chapter in Book or Conference Publication/ProceedingConference Publicationpeer-review

11 Citations (Scopus)

Abstract

The global digital landscape is changing rapidly with the advances in science and technology. A plethora of new breakthroughs are being made every day in several different fields, such as Internet infrastructure, Web 3.0, and AR/VR technologies. With these ever-increasing digital advancements, cybersecurity threats and vulnerabilities are also being exploited daily. In recent times, another critical vulnerability 'Log4jshell' is identified in the logging tool Log4j. The ubiquity of this logging tool among many worldwide online services has exposed millions of devices to this vulnerability. In order to address this critical issue, the paper presents a framework for improving system security against Log4j attacks. The proposed framework deploys an in-house honeypot to detect and defend against various types of Log4j payloads. Experimental results prove the efficiency and accuracy of Log4j payload detection with an average execution time of 80.104 milliseconds for all utilized HTTP methods. In addition, the paper describes Log4shell vulnerabilities, webhooks, and provides a comparative assessment with previously proposed solutions.

Original languageEnglish
Title of host publication2022 33rd Irish Signals and Systems Conference, ISSC 2022
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9781665452274
DOIs
Publication statusPublished - 2022
Event33rd Irish Signals and Systems Conference, ISSC 2022 - Cork, Ireland
Duration: 9 Jun 202210 Jun 2022

Publication series

Name2022 33rd Irish Signals and Systems Conference, ISSC 2022

Conference

Conference33rd Irish Signals and Systems Conference, ISSC 2022
Country/TerritoryIreland
CityCork
Period9/06/2210/06/22

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 9 - Industry, Innovation, and Infrastructure
    SDG 9 Industry, Innovation, and Infrastructure

Keywords

  • Detection
  • FastAPI
  • Log4j
  • Low interaction honeypot
  • Python
  • Webhooks

Fingerprint

Dive into the research topics of 'Log4jPot: Effective Log4Shell Vulnerability Detection System'. Together they form a unique fingerprint.

Cite this