Deceptive directories and “vulnerable” logs: a honeypot study of the LDAP and log4j attack landscape

Shreyas Srinivasa, Jens Myrup Pedersen, Emmanouil Vasilomanolakis

Research output: Contribution to book/anthology/report/conference proceedingArticle in proceedingResearchpeer-review

8 Citations (Scopus)
229 Downloads (Pure)

Abstract

The Lightweight Directory Access Protocol (LDAP) has been widely used to query directory services. It is mainly utilized for reading, writing, and searching directory services like the Active Directory. The vast adoption of LDAP for authentication has entailed several attack attempts like injection attacks and unauthorized access due to third-party key storage. Furthermore, recent vulnerabilities discovered in libraries like the Log4j can lead adversaries to obtain unauthorized information from the directory services through pivoting attacks. Moreover, the LDAP can be configured to operate on UDP, motivating adversaries to exploit it for Distributed Reflection Denial of Service attacks (DRDoS). This paper presents a study of attacks on the LDAP by deploying honeypots that simulate multiple profiles that support the LDAP service and correlating the attack datasets obtained from honeypots deployed by the Honeynet Project community. We observe a total of 39,388 malicious events targeting the honeypots and discover 273 unique attack sources performing pivot attacks in a period of one month.

Original languageEnglish
Title of host publicationProceedings - 7th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2022
Number of pages6
PublisherIEEE
Publication dateMar 2022
Pages442-447
ISBN (Electronic)978-1-6654-9560-8
DOIs
Publication statusPublished - Mar 2022
Event2022 IEEE European Symposium on Security and Privacy Workshops - Genoa, Italy
Duration: 6 Jun 202210 Jun 2022

Conference

Conference2022 IEEE European Symposium on Security and Privacy Workshops
Country/TerritoryItaly
CityGenoa
Period06/06/202210/06/2022
SeriesIEEE European Symposium on Security and Privacy Workshops (EuroS&PW)
ISSN2768-0657

Keywords

  • Deception
  • Honeypots
  • LDAP
  • LDAP attacks

Fingerprint

Dive into the research topics of 'Deceptive directories and “vulnerable” logs: a honeypot study of the LDAP and log4j attack landscape'. Together they form a unique fingerprint.

Cite this