DC FieldValueLanguage
dc.contributor.authorHiesgen, Raphael-
dc.contributor.authorNawrocki, Marcin-
dc.contributor.authorSchmidt, Thomas C.-
dc.contributor.authorWählisch, Matthias-
dc.date.accessioned2026-03-19T09:08:42Z-
dc.date.available2026-03-19T09:08:42Z-
dc.date.issued2024-08-07-
dc.identifier.issn1932-4537en_US
dc.identifier.urihttps://hdl.handle.net/20.500.12738/19097-
dc.description.abstractOn December 10, 2021, Log4Shell was disclosed to the public and was quickly recognized as a most severe vulnerability. It exploits a bug in the wide-spread Log4j library that allows for critical remote-code-execution (RCE). Any service that uses this library and exposes an interface to the Internet is potentially vulnerable. In this paper, we report about a measurement study starting with the day of disclosure. We follow the rush of scanners during the first two months after the disclosure and observe the development of the Log4Shell scans in the subsequent year. Based on traffic data collected at several vantage points we analyze the payloads sent by researchers and attackers. We find that the initial rush of scanners ebbed quickly, but continued in waves throughout 2022. Benign scanners showed interest only in the first days after the disclosure, whereas malicious scanners continue to target the vulnerability.During both periods, a single entity appears responsible for the majority of the malicious activities.en
dc.language.isoenen_US
dc.publisherIEEEen_US
dc.relation.ispartofIEEE transactions on network and service managementen_US
dc.subjectInternet Securityen_US
dc.subjectCritical Vulnerabilityen_US
dc.subjectSecurity Measurementen_US
dc.subject.ddc004: Informatiken_US
dc.titleThe Log4j incident : a comprehensive measurement study of a critical vulnerabilityen
dc.typeArticleen_US
dc.description.versionPeerRevieweden_US
tuhh.container.endpage5934en_US
tuhh.container.issue6en_US
tuhh.container.startpage5921en_US
tuhh.container.volume21en_US
tuhh.oai.showtrueen_US
tuhh.publication.instituteDepartment Informatik (ehemalig, aufgelöst 10.2025)en_US
tuhh.publication.instituteFakultät Technik und Informatik (ehemalig, aufgelöst 10.2025)en_US
tuhh.publisher.doi10.1109/TNSM.2024.3440188-
tuhh.type.opus(wissenschaftlicher) Artikel-
dc.rights.cchttps://creativecommons.org/licenses/by/4.0/en_US
dc.type.casraiJournal Article-
dc.type.diniarticle-
dc.type.driverarticle-
dc.type.statusinfo:eu-repo/semantics/publishedVersionen_US
dcterms.DCMITypeText-
item.creatorOrcidHiesgen, Raphael-
item.creatorOrcidNawrocki, Marcin-
item.creatorOrcidSchmidt, Thomas C.-
item.creatorOrcidWählisch, Matthias-
item.grantfulltextnone-
item.creatorGNDHiesgen, Raphael-
item.creatorGNDNawrocki, Marcin-
item.creatorGNDSchmidt, Thomas C.-
item.creatorGNDWählisch, Matthias-
item.openairetypeArticle-
item.openairecristypehttp://purl.org/coar/resource_type/c_6501-
item.languageiso639-1en-
item.fulltextNo Fulltext-
item.cerifentitytypePublications-
crisitem.author.deptDepartment Informatik (ehemalig, aufgelöst 10.2025)-
crisitem.author.deptDepartment Informatik (ehemalig, aufgelöst 10.2025)-
crisitem.author.orcid0000-0002-0956-7885-
crisitem.author.parentorgFakultät Technik und Informatik (ehemalig, aufgelöst 10.2025)-
crisitem.author.parentorgFakultät Technik und Informatik (ehemalig, aufgelöst 10.2025)-
Appears in Collections:Publications without full text
Show simple item record

Google ScholarTM

Check

HAW Katalog

Check

Add Files to Item

Note about this record


This item is licensed under a Creative Commons License Creative Commons