{"id":39555,"date":"2022-07-15T05:52:00","date_gmt":"2022-07-15T05:52:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/39555"},"modified":"2022-07-15T05:52:00","modified_gmt":"2022-07-15T05:52:00","slug":"log4shell-on-its-way-to-becoming-endemic","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=39555","title":{"rendered":"Log4Shell on its way to becoming \u2018endemic\u2019"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/log4shell-on-its-way-to-becoming-endemic.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>The Log4Shell vulnerability in Apache Log4j, which caused consternation across the technology industry <a href=\"https:\/\/www.computerweekly.com\/news\/252510860\/What-is-Log4Shell-and-why-are-we-panicking-about-it\">when it surfaced at the end of 2021<\/a>, will be with us for a long time to come, perhaps as long as a decade, according to a report produced by the US\u2019s Cyber Safety Review Board (CSRB), a panel of experts drawn from various government agencies and the private sector.<\/p>\n<p>The CSRB, which was established by president Joe Biden <a href=\"https:\/\/www.techtarget.com\/iotagenda\/feature\/Cybersecurity-executive-order-2021-pushes-IoT-security\">via an executive order in 2021<\/a>, has been poring over exactly what happened with Log4j, a pervasive and ubiquitous Java-based logging library that has been incorporated into thousands of systems over the years.<\/p>\n<p>Tracked as CVE-2021-44228, the Log4Shell remote code execution (RCE) vulnerability is considered very easy to exploit and has been described variously as a \u201cdesign failure of catastrophic proportions\u201d and a \u201cworst-case scenario\u201d.<\/p>\n<p>Now, more than six months on, it has become abundantly clear that despite the urgency with which the industry stepped up to address it, Log4Shell is by no means over, as was made clear by CSRB chair Robert Silver, under secretary for policy at the Department for Homeland Security, and deputy chair Heather Adkins, senior director of security engineering at Google.<\/p>\n<p>\u201cLog4j remains deeply embedded in systems, and even within the short period available for our review, community stakeholders have identified new compromises, new threat actors and new learnings,\u201d wrote Silver and Adkins. \u201cWe must remain vigilant against the risks associated with this vulnerability, and apply the best practices described in this review.<\/p>\n<p>\u201cThe Board assesses that Log4j is an \u2018endemic vulnerability\u2019 and that vulnerable instances of Log4j will remain in systems for many years to come, perhaps a decade or longer. Significant risk remains.\u201d<\/p>\n<p>At the time of writing, the CSRB said it was not aware of any significant attacks on critical national infrastructure (CNI) that have exploited Log4Shell, and also noted that general exploitation occurred at lower levels than was at first predicted, given its severity.<\/p>\n<p>However, it further noted that these conclusions were not easy to draw because much of the evidence is anecdotal and there are no real sources to understand exploitation trends across geographies and industries that are not linked to commercial cyber interests.<\/p>\n<p>The CSRB further assessed that in the response to Log4Shell, many things went right, particularly in the Apache Software Foundation\u2019s (ASF\u2019s) response, which quickly recognised the severity of the vulnerability and was able to fall back on well-established software development processes to remediate it. The CSRB also praised the response of the cyber industry in general, with vendors quick to produce guidance.<\/p>\n<p>Yet, it added, organisations clearly struggled to respond to the event, with much of the hard work of upgrading vulnerable systems still far from complete. Also, Log4Shell exposed troubling security risks inherent to the open source community, which the report said was inadequately resourced to ensure that code is developed in accordance with security best practice.<\/p>\n<p>The report went on to make 19 key recommendations, which are broken into four categories, set out below, <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/publications\/CSRB-Report-on-Log4-July-11-2022_508.pdf\">while the full report can be downloaded for review here<\/a>.<\/p>\n<p>Terry Olaes, sales engineering director at <a href=\"https:\/\/www.skyboxsecurity.com\/\">Skybox Security<\/a>, a California-based threat management specialist, has been tracking Log4Shell since the vulnerability was first disclosed in December 2021. He described the report\u2019s findings as unfortunate, but not surprising given Log4j\u2019s widespread use.<\/p>\n<p>\u201cLog4j threats expose victims that lack mature cyber security risk models to attacks that have RCE vectors like ransomware, and there will likely be many attacks associated with this vulnerability for years to come,\u201d said Olaes.&nbsp;<\/p>\n<p>\u201cIn the years ahead, threat actors will innovate new and creative ways to exploit common tools like Log4j. As a result, preventing breaches requires immediately minimising your exposure through smart and targeted mitigation.<\/p>\n<p>\u201cFor a widespread vulnerability like Log4j, patching all of the instances isn\u2019t practical. Not only is it time-consuming, it\u2019s also hugely costly. History shows that the \u2018patch everything\u2019 strategy is a monumental waste of effort due to the fact that, typically, it\u2019s a very small subset of devices that are actually exposed to the attack itself. That is why it is crucial to take a more proactive approach to vulnerability management by learning to identify and prioritise exposed vulnerabilities across the entire threat landscape.\u201d<\/p>\n<p>Commenting further on the CSRB review, <a href=\"https:\/\/www.synopsys.com\/software-integrity\/cybersecurity-research-center.html\">Synopsys Cybersecurity Research Centre<\/a> principal strategist Tim Mackey said: \u201cRarely do we get a comprehensive review of the impact and root causes of a cyber incident so quickly after the incident occurred, but that is precisely what we have from the CSRB in their report on Log4Shell and Log4j.<\/p>\n<p>\u201cOpen source software is fundamentally managed differently than commercial software, but open source software plays a key role in the success of commercial software. The long-tail scenario outlined in the report is one we\u2019ve seen with countless past vulnerabilities, and one that favours attackers since their success is based on having at least one victim who hasn\u2019t patched their systems.<\/p>\n<p>\u201cGiven that management of open source software is different than commercial software, and open source powers commercial software, reliance on a commercial vendor to alert consumers of a problem presumes that the vendor is properly managing their usage of open source and that they are able to identify and alert all users of their impacted software \u2013 even if support for that software has ended.<\/p>\n<p>Mackey added: \u201cWith patch management being a challenge at the best of times, to mitigate the risk of unknown open source governance within vendors, software consumers should implement a trust-but-verify model to validate whether the software they\u2019re given doesn\u2019t contain unpatched vulnerabilities.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Log4Shell vulnerability in Apache Log4j, which caused consternation across the technology industry when it surfaced at the end of 2021, will be with us for a long time to come, perhaps as long as a decade, according to a report produced by the US\u2019s Cyber Safety Review Board (CSRB), a panel of experts drawn [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":39556,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-39555","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39555","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39555"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39555\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/39556"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39555"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39555"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39555"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}