A Longitudinal Measurement Study of Log4Shell Exploitation from an Active Network Telescope

📅 2026-01-07
🏛️ arXiv.org
📈 Citations: 0
Influential: 0
📄 PDF

career value

250K/year
🤖 AI Summary
Following the disclosure of the Log4Shell vulnerability, its long-term, cross-regional exploitation dynamics have lacked systematic observation. This study leverages an active network telescope deployed in India to conduct a longitudinal measurement of Log4Shell-related traffic from December 2021 to October 2025, offering the first South Asian perspective on post-outbreak exploitation trends. Our analysis reveals persistent attack activity spanning multiple years, increasing centralization of scanning and callback infrastructure, and growing use of payload obfuscation. Through traffic capture, payload decoding, infrastructure clustering, and cross-regional comparison, we further identify significant shifts in protocol and port usage. These findings underscore the critical importance of sustained, multi-regional monitoring for understanding the full lifecycle of critical software vulnerabilities.

Technology Category

Application Category

📝 Abstract
The disclosure of the Log4Shell vulnerability in December 2021 led to an unprecedented wave of global scanning and exploitation activity. A recent study provided important initial insights, but was largely limited in duration and geography, focusing primarily on European and U.S. network telescope deployments and covering the immediate aftermath of disclosure. As a result, the longer-term evolution of exploitation behavior and its regional characteristics has remained insufficiently understood. In this paper, we present a longitudinal measurement study of Log4Shell-related traffic observed between December 2021 and October 2025 by an active network telescope deployed in India. This vantage point enables examination of sustained exploitation dynamics beyond the initial outbreak phase, including changes in scanning breadth, infrastructure reuse, payload construction, and destination targeting. Our analysis reveals that Log4Shell exploitation persists for several years after disclosure, with activity gradually concentrating around a smaller set of recurring scanner and callback infrastructures, accompanied by an increase in payload obfuscation and shifts in protocol and port usage. A comparative analysis and observations with the benchmark study validate both correlated temporal trends and systematic differences attributable to vantage point placement and coverage. Subsequently, these results demonstrate that Log4Shell remains active well beyond its initial disclosure period, underscoring the value of long-term, geographically diverse measurement for understanding the full lifecycle of critical software vulnerabilities.
Problem

Research questions and friction points this paper is trying to address.

Log4Shell
vulnerability exploitation
longitudinal measurement
network telescope
cybersecurity
Innovation

Methods, ideas, or system contributions that make the work stand out.

Longitudinal Measurement
Active Network Telescope
Log4Shell Exploitation
Geographic Diversity
Payload Obfuscation
🔎 Similar Papers
No similar papers found.
A
Aakash Singh
Big Data Research and Supercomputing Division, CSIR Fourth Paradigm Institute (CSIR-4PI), Bengaluru, India
Kuldeep Singh Yadav
Kuldeep Singh Yadav
Scientist, CSIR||Post-Doc Fellow, Indian Institute of Technology Delhi
Deep LearningComputer Vision and Image ProcessingPattern RecognitionHBI and HCI
V
V. Anil Kumar
Big Data Research and Supercomputing Division, CSIR Fourth Paradigm Institute (CSIR-4PI), Bengaluru, India
S
Samiran Ghosh
Big Data Research and Supercomputing Division, CSIR Fourth Paradigm Institute (CSIR-4PI), Bengaluru, India
P
Pranita Baro
Big Data Research and Supercomputing Division, CSIR Fourth Paradigm Institute (CSIR-4PI), Bengaluru, India
B
Basavala Bhanu Prasanth
Big Data Research and Supercomputing Division, CSIR Fourth Paradigm Institute (CSIR-4PI), Bengaluru, India