{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T03:32:03Z","timestamp":1785900723457,"version":"3.56.0"},"reference-count":69,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2024,12,1]],"date-time":"2024-12-01T00:00:00Z","timestamp":1733011200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"German Federal Ministry of Education and Research (BMBF) within the projects PRIMEnet and IPv6Explorer"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw. Serv. Manage."],"published-print":{"date-parts":[[2024,12]]},"DOI":"10.1109\/tnsm.2024.3440188","type":"journal-article","created":{"date-parts":[[2024,8,7]],"date-time":"2024-08-07T17:44:33Z","timestamp":1723052673000},"page":"5921-5934","source":"Crossref","is-referenced-by-count":23,"title":["The Log4j Incident: A Comprehensive Measurement Study of a Critical Vulnerability"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1676-8108","authenticated-orcid":false,"given":"Raphael","family":"Hiesgen","sequence":"first","affiliation":[{"name":"Department Informatik, HAW Hamburg, Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Marcin","family":"Nawrocki","sequence":"additional","affiliation":[{"name":"ASERT, NETSCOUT, Westford, MA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0956-7885","authenticated-orcid":false,"given":"Thomas C.","family":"Schmidt","sequence":"additional","affiliation":[{"name":"Department Informatik, HAW Hamburg, Hamburg, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3825-2807","authenticated-orcid":false,"given":"Matthias","family":"W\u00e4hlisch","sequence":"additional","affiliation":[{"name":"Institute of Systems Architecture, Faculty of Computer Science, TU Dresden, Dresden, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"CVE-2015-0565","year":"2022"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3399742"},{"key":"ref3","volume-title":"CVE-2017-5753","year":"2022"},{"key":"ref4","volume-title":"CVE-2017-5715","year":"2022"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/2663716.2663755"},{"key":"ref6","volume-title":"CVE-2014-0160","year":"2022"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/3555050.3569123"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/tnsm.2022.3195406"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/tnsm.2023.3327455"},{"key":"ref10","volume-title":"Here\u2019s How Stack Overflow Users Responded to Log4Shell, The Log4j Vulnerability Affecting Almost Everyone","year":"2022"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3199674"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450033"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.23919\/tma62044.2024.10559089"},{"key":"ref14","first-page":"1","article-title":"The race to the vulnerable: Measuring the Log4j shell incident","volume-title":"Proc. Netw. Traffic Meas. Anal. Conf. (TMA)","author":"Hiesgen"},{"key":"ref15","volume-title":"Apache Log4j Security Vulnerabilities","year":"2022"},{"key":"ref16","volume-title":"CVE-2021-44228","year":"2022"},{"key":"ref17","volume-title":"Restrict LDAP access via JNDI","author":"Goers","year":"2022"},{"key":"ref18","volume-title":"CVE-2021-45046","year":"2022"},{"key":"ref19","volume-title":"CVE-2021-45105","year":"2022"},{"key":"ref20","volume-title":"CVE-2021-44832","year":"2022"},{"key":"ref21","volume-title":"CVE-2021-44228 Detail","year":"2022"},{"key":"ref22","volume-title":"Understanding the impact of Apache Log4j vulnerability","year":"2022"},{"key":"ref23","volume-title":"JNDI Lookup Plugin Support","year":"2022"},{"key":"ref24","article-title":"Apache Log4j bug: China\u2019s industry ministry pulls support from Alibaba Cloud for not reporting flaw to government first","year":"2022"},{"key":"ref25","article-title":"Chinese regulators suspend Alibaba Cloud over failure to report Log4j vulnerability","year":"2022"},{"key":"ref26","volume-title":"Matthew Prince (Cloudflare)","year":"2022"},{"key":"ref27","volume-title":"Threat Advisory: Critical Apache Log4j Vulnerability Being Exploited in the Wild","year":"2022"},{"key":"ref28","volume-title":"Threat alert: Log4j vulnerability has been adopted by two Linux Botnets","year":"2022"},{"key":"ref29","volume-title":"Log4j Attack Payloads in the Wild","year":"2022"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3538969.3539009"},{"key":"ref31","volume-title":"Guidance for Preventing, Detecting, and Hunting for Exploitation of the Log4j 2 Vulnerability","year":"2022"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14722\/madweb.2022.23010"},{"key":"ref33","volume-title":"A journey from JNDI\/LDAP manipulation to remote code execution dream land","author":"Mu\u00f1oz","year":"2022"},{"key":"ref34","first-page":"431","article-title":"Spoki: Unveiling a new wave of scanners through a reactive network telescope","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Hiesgen"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/2687357.2687363"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/HPEC49654.2021.9622790"},{"key":"ref37","article-title":"A survey on honeypot software and data analysis","author":"Nawrocki","year":"2016","journal-title":"arXiv:1608.06249"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp57164.2023.00041"},{"key":"ref39","volume-title":"The UCSD Network Telescope","year":"2012"},{"key":"ref40","volume-title":"Log4shell-detector","author":"Roth","year":"2021"},{"key":"ref41","volume-title":"MaxMind\u2014GeoLite country","year":"2023"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/1971162.1971171"},{"key":"ref43","volume-title":"The interconnection database","year":"2019"},{"key":"ref44","volume-title":"IP lookup API","year":"2024"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2013.2297678"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.5555\/3241189.3241275"},{"key":"ref47","volume-title":"Google-crawler (user-agents)","year":"2022"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052571"},{"key":"ref49","volume-title":"Log4j Vulnerability: Attackers Shift Focus From LDAP to RMI","year":"2022"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3355369.3355595"},{"key":"ref51","volume-title":"Lightweight directory access protocol (LDAP): Uniform resource locator","author":"Smith","year":"2006"},{"key":"ref52","volume-title":"VirusTotal","year":"2024"},{"key":"ref53","first-page":"605","article-title":"ZMap: Fast Internet-wide scanning and its security applications","volume-title":"Proc. 22nd USENIX Secur. Symp.","author":"Durumeric"},{"key":"ref54","volume-title":"Log4Shell still has sting in the tail","year":"2022"},{"key":"ref55","volume-title":"Malicious Cyber Actors Continue to Exploit Log4Shell in VMware Horizon Systems","year":"2022"},{"key":"ref56","volume-title":"Log4Shell a year on\u2014A year after discovery, the Log4Shell vulnerability is still making itself felt","author":"Grustniy","year":"2022"},{"key":"ref57","volume-title":"Acknowledged scanners","author":"Collins","year":"2022"},{"key":"ref58","volume-title":"I hunt TR-069 admins: DEF CON 22 talk","author":"Tal","year":"2017"},{"key":"ref59","first-page":"233","article-title":"Watching the weak link into your home: An inspection and monitoring toolkit for TR-069","volume-title":"Proc. ACNS","author":"Hils"},{"key":"ref60","volume-title":"New Mirai worm knocks 900K Germans offline","author":"Krebs","year":"2016"},{"key":"ref61","volume-title":"Shodan\u2014Search engine for the Internet of everything","year":"2014"},{"key":"ref62","volume-title":"xmrig_setup","year":"2023"},{"key":"ref63","volume-title":"Log4shell Vulnerabilities","year":"2022"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/SecDev53368.2022.00016"},{"key":"ref65","volume-title":"MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations","year":"2022"},{"key":"ref66","volume-title":"North Korea\u2019s Lazarus hackers are exploiting Log4j flaw to hack US energy companies","year":"2022"},{"key":"ref67","volume-title":"Iranian Government-Sponsored APT Actors Compromise Federal Network, Deploy Crypto Miner, Credential Harvester","year":"2022"},{"key":"ref68","volume-title":"Log4shell exploits now used mostly for DDoS botnets, cryptominers","author":"Toulas","year":"2022"},{"key":"ref69","volume-title":"Impact of Log4Shell Bug was Overblown, Say Researchers","author":"Muncaster","year":"2023"}],"container-title":["IEEE Transactions on Network and Service Management"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/4275028\/10807691\/10628102.pdf?arnumber=10628102","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,20]],"date-time":"2024-12-20T06:12:14Z","timestamp":1734675134000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10628102\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12]]},"references-count":69,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tnsm.2024.3440188","relation":{},"ISSN":["1932-4537","2373-7379"],"issn-type":[{"value":"1932-4537","type":"electronic"},{"value":"2373-7379","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12]]}}}