Log4shell: Redefining the Web Attack Surface

D. Everson, Long Cheng, Zhenkai Zhang
{"title":"Log4shell: Redefining the Web Attack Surface","authors":"D. Everson, Long Cheng, Zhenkai Zhang","doi":"10.14722/madweb.2022.23010","DOIUrl":null,"url":null,"abstract":"—The log4shell vulnerability has been called one of the most significant cybersecurity vulnerabilities in recent history. For weeks after initial disclosure, companies around the globe scrambled to respond by patching their systems or by applying mitigating security measures to protect systems that could not be readily patched. There are many possible ways to detect if and where an organization is vulnerable to log4shell, each with advantages and disadvantages. Penetration testing in particular is one possible solution, though its results can be misleading if not interpreted in the proper context. Mitigation measures have varying degrees of success: Web Application Firewalls (WAFs) could be bypassed, whereas our analysis revealed that outbound network restrictions would have provided an effective protection given the rapidly evolving patch cycle. Ultimately, log4shell should change the way we look at web attack surfaces; doing so will ensure we can be better prepared for the next critical zero-day Remote Code Execution (RCE) vulnerability.","PeriodicalId":424703,"journal":{"name":"Proceedings 2022 Workshop on Measurements, Attacks, and Defenses for the Web","volume":"3 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"1900-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Proceedings 2022 Workshop on Measurements, Attacks, and Defenses for the Web","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.14722/madweb.2022.23010","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6

Abstract

—The log4shell vulnerability has been called one of the most significant cybersecurity vulnerabilities in recent history. For weeks after initial disclosure, companies around the globe scrambled to respond by patching their systems or by applying mitigating security measures to protect systems that could not be readily patched. There are many possible ways to detect if and where an organization is vulnerable to log4shell, each with advantages and disadvantages. Penetration testing in particular is one possible solution, though its results can be misleading if not interpreted in the proper context. Mitigation measures have varying degrees of success: Web Application Firewalls (WAFs) could be bypassed, whereas our analysis revealed that outbound network restrictions would have provided an effective protection given the rapidly evolving patch cycle. Ultimately, log4shell should change the way we look at web attack surfaces; doing so will ensure we can be better prepared for the next critical zero-day Remote Code Execution (RCE) vulnerability.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
Log4shell:重新定义Web攻击面
- log4shell漏洞被称为近期历史上最重要的网络安全漏洞之一。在最初披露后的数周内,全球各地的公司争相做出回应,要么给自己的系统打补丁,要么采用缓解安全措施来保护那些不容易打补丁的系统。有许多可能的方法可以检测组织是否以及在哪里容易受到log4shell的攻击,每种方法都有优缺点。特别是渗透测试是一种可能的解决方案,尽管如果不在适当的上下文中解释其结果可能会产生误导。缓解措施取得了不同程度的成功:可以绕过Web应用防火墙(waf),而我们的分析显示,考虑到快速发展的补丁周期,出站网络限制将提供有效的保护。最终,log4shell应该改变我们看待web攻击面的方式;这样做将确保我们能够更好地为下一个关键的零日远程代码执行(RCE)漏洞做好准备。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
What the Fork? Finding and Analyzing Malware in GitHub Forks Log4shell: Redefining the Web Attack Surface What Storage? An Empirical Analysis of Web Storage in the Wild Characterizing the Adoption of Security.txt Files and their Applications to Vulnerability Notification P4DDPI: Securing P4-Programmable Data Plane Networks via DNS Deep Packet Inspection
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1