A Rule Based Secure Network System - Prevents Log4jshell and SSH Intrusions

M A Samid Arsalan, S Suryaraman, G. Sujatha · 2023

There is a rapid growth in the field of technology and with this growth, the need for security is very much necessary to protect the privacy of everyone who uses their computers on a daily basis. Applications that use Java are everywhere around us and Log4j is a fast and reliable framework that is written in Java to log all the information which occurs in the application (mainly errors) which is beneficial to the developers. The log4j package is present under the Apache Software License, which is completely an open-source license which is certified by the open source initiative, implying that it was widely available to use and modify the same as per ones requirement [1]. As this particular java utility was used to maliciously launch RCE (Remote Code Execution) to execute commands that puts the user data at risk of theft and malicious intent, and the number of devices that used this particular API was in billions. As Java is the most-used programming language for IoT app development and typically includes Log4j. Since the Log4j vulnerability is very easy to exploit, this puts the other devices within the IoT product ecosystem at risk. The proposed model is that the honeypot deployed has a low interaction and that it not only alerts the security team but also analyses the payload pattern so that a rule can be created in the firewall to prevent such attacks in the future. The honeypot also detects SSH based attacks and alerts for any such potential attacks. This rule adds another layer of security on top of having a honeypot.

Read the paper · More papers on PaperTik