ChainSecure - A Scalable and Proactive Solution for Protecting Blockchain Applications Using SDN
Abstract
Nowadays, blockchain is seen as one of the main technological innovations. Many applications can rely on the blockchain to secure their exchanges. However, applications with private interest cannot rely on public blockchains. First, in a public blockchain, anyone can read the whole data of the blockchain. Second, anyone can participate to the "consensus process"; the process for determining the validity of each transaction. Consortium and fully private blockchains aim to combine forcefulness of blockchains with controlled consensus process and stricter permissions for deploying a node and joining the blockchain network. In both consortium and fully private blockchains, the number of peers on the blockchain network is very small in comparison with public blockchain. Nonetheless, by targeting the nodes of blockchains, an attacker can easily manage the whole blockchain and takes control of the consensus process to validate his illegitimate transactions. In this paper, to defend blockchain nodes from DNS amplification attacks, we propose a scalable and proactive solution in the context of software defined networks (SDN), named ChainSecure. ChainSecure consists of 3 schemes: (1) StateMap, a novel stateful mapping scheme (SMS) to perform a mapping one-to-one between DNS request and response; (2) Entropy calculation scheme (ECS) to measure the disorder / randomness of data using sFlow in order to detect illegitimate flows; (3) DNS DDoS Mitigation (DDM) module to effectively mitigate illegitimate DNS requests. The experimental results show that ChainSecure protects blockchain nodes and can detect/mitigate the attack quickly to achieve high accuracy in detecting illegitimate DNS traffic making it a promising solution to protect blockchain nodes from DNS amplification attacks.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.