Log Poisoning Attacks in IoT: Methodologies, Evasion, Detection, Mitigation, and Criticality Analysis

Haitham Ameen Noman, Osama M. F. Abu‐Sharkh, Sinan Ameen Noman · IEEE Access · 2024

Log poisoning is a cyber-attack where adversaries manipulate systems’ log files to conceal their activities or execute malicious codes. This paper presents a thorough examination of log poisoning attacks, with a focus on demonstrating methodologies applied to prevalent Internet of Things (IoT) platforms, such as the Raspberry Pi. We introduce a novel technique that circumvents the Linux-based devices system’s protective mechanisms which truncate malicious injected code in sensitive log files. Furthermore, a novel persistence technique that allows the attacker to maintain a persistent connection with the Linux-based target device was introduced. Moreover, we propose an evasive technique that enables adversaries to effectively conceal their log poisoning attacks by executing them through encrypted tunnels using a virtual private network (VPN). Through Intrusion Modes and Criticality Analysis (IMECA), we analyze the severity and potential impact of these attacks and propose mitigation strategies to avoid the occurrence of such attacks in order to maintain the confidentiality, integrity, and reliability of IoT ecosystems. As a further step to counteract the threat, we designed a Python script that detects and mitigates log poisoning attacks, specifically against malicious codes that are injected into logs without requiring the log file to be set as executable.

Read the paper · More papers on PaperTik