The healthcare sector increasingly explores Distributed Ledger Technology (DLT) and Health Web 3.0 Decentralized Applications (DApps) as promising solutions for patient-centric data management, data sovereignty, and privacy-preserving systems. Despite significant research at the intersection of blockchain and healthcare, current efforts predominantly address isolated technical challenges—focusing narrowly on specific mechanisms such as confidentiality, privacy, or individual smart contract vulnerabilities. Even cybersecurity assessments typically examine discrete attack vectors rather than comprehensive threat landscapes. This fragmented approach limits our ability to build trustworthy systems and delays real-world adoption, as stakeholders lack frameworks to holistically evaluate security posture. This study addresses this gap by conducting a comprehensive threat modeling analysis of Health Web 3.0 DApps, taking into account the complex and interconnected security challenges inherent in blockchain-based healthcare systems. We employ a multi-framework approach integrating LINDDUN threat modeling methodology, OWASP Top 10 Smart Contract Vulnerabilities catalog, and Threat Dragon analytical tool to systematically identify, categorize, and evaluate security risks across the entire application stack. Our analysis maps threats spanning smart contract design flaws, cross-chain interaction vulnerabilities, decentralized identity management weaknesses, unauthorized data access risks, and denial-of-service attack vectors. The primary contribution of this work is demonstrating the critical importance and practical value of holistic threat modeling in blockchain healthcare systems. Our findings reveal interdependencies between seemingly isolated vulnerabilities and show how comprehensive security assessment enhances data privacy protection, smart contract integrity, and overall application resilience. This research provides stakeholders with a systematic methodology for deriving trust in blockchain healthcare solutions, advancing both regulatory compliance and user confidence in decentralized medical data management systems.
Cloud identity management has evolved from a purely technical concern into a fundamental pillar of digital society, creating profound impacts that extend far beyond organizational boundaries. Modern cloud-based identity and access management systems serve as critical infrastructure enabling access to essential services including healthcare, education, government benefits, and financial services. These systems incorporate advanced technical mechanisms such as multi-factor authentication, single sign-on, zero trust architecture, and artificial intelligence-driven fraud detection to establish secure and inclusive digital environments. The transformation to cloud-based architectures addresses traditional limitations of on-premises systems while introducing new capabilities for digital inclusion through device-agnostic authentication, accessibility-first design, and multilingual support. However, this evolution presents significant challenges including privacy concerns arising from data aggregation, potential government surveillance, and algorithmic bias in automated decision-making systems. Strategic implementation through public-private partnerships, investment in open source components, and adoption of emerging technologies such as quantum-resistant cryptography and distributed ledger integration shapes the societal impact of these systems. The technical decisions made in designing and implementing cloud identity infrastructure have far-reaching implications for social equity, democratic participation, and economic opportunity in an increasingly digital world.
Jesus Gama-Rodnguez, Ekam Puri Nieto, Juan Francisco Martínez Gil, Agustín Marín Frutos
Exploration in the crucial role of cyber threat intelligence (CTI) sharing and lifecycle security in IoT ecosystems. It examines how the ERATOSTHENES project leverages distributed ledger technology (DLT) and an inter-ledger approach to facilitate secure and privacy-preserving CTI exchange across different domains. The chapter also discusses the use of Manufacturer Usage Description (MUD) files, including the proposed Threat MUD extension, to manage security configurations and mitigation actions throughout the device lifecycle. Additionally, it highlights the integration of these components to achieve a system that dynamically responds to cybersecurity incidents, ensuring the ongoing protection of devices and domains.
Mohammed Ibraheem Hussein, Ohood Saadoon Hlail, Asma Ibrahim Hussein, Amjed Abbas Ahmed · 6 authors
Balancing efficient threat detection with data privacy becomes increasingly difficult as cyber threats develop in complexity. The Adaptive Zero-Knowledge Threat Hunting Framework (AZTH), a revolutionary integration of zero-knowledge proofs (ZKP) and artificial intelligence (AI) for private and secure cybersecurity operations, is presented in the presented study. AZTH maintains strong confidentiality regarding sensitive data yet uses federated learning, quantum-resistant cryptography, and dynamic deception systems to improve threat intelligence sharing as well as real-time threat mitigation. Together with an assessment of its efficacy in several operating situations, the architecture, approach, and possible uses of the framework are given.
Francesco Salzano, Lodovica Marchesi, Cosmo Kevin Antenucci, Simone Scalabrino · 7 authors
Abstract In this paper, we investigate the strategies adopted by Solidity developers to fix security vulnerabilities in smart contracts. Vulnerabilities are categorized using the DASP TOP 10 taxonomy, and fixing strategies are extracted from 364 commits collected from open-source Solidity projects on GitHub. Each commit was selected through a two-phase process: an initial filter using natural language processing techniques, followed by manual validation. We assessed whether these fixes adhere to established academic guidelines. Our analysis shows that 60.55% of the commits aligned with at least one literature-based recommendation, particularly for well-documented vulnerability types such as Reentrancy and Arithmetic. However, adherence dropped significantly for categories like Denial of Service, Time Manipulation, and Bad Randomness, highlighting gaps between academic best practices and real-world developer behavior. From the remaining 143 non-aligned commits, we identified 27 novel fixing strategies not previously discussed in the literature. To evaluate their quality, we conducted a structured questionnaire involving 9 experts from both academia and industry. Their feedback indicated high perceived effectiveness of the new fixes, especially for vulnerabilities like Reentrancy and Unchecked Return Values. Generalizability received more varied responses, suggesting context-specific applicability. Finally, we performed a post-fix evolution analysis on over 6700 subsequent commits to assess the long-term stability of the fixes. Most patches remained unchanged, confirming their persistence in production code. Our findings offer practical insights into how vulnerabilities are fixed in smart contracts today, reveal promising emerging patterns, and help bridge the gap between academic guidelines and developer practices.
Electronic Health Records (EHRs) are now a necessary component of contemporary healthcare, but managing them presents a number of security, privacy, and interoperability issues. In order to solve these issues, this study introduces a unique framework for EHR management that combines four cutting-edge technologies: blockchain, Zero-Knowledge Proofs (ZKP), Ciphertext-Policy Attribute-Based Encryption (CP-ABE), and InterPlanetary File System (IPFS). Our solution makes use of the Ethereum blockchain for transparent and safe record-keeping, IPFS for efficient and decentralized data storage, CP-ABE for fine-grained access control, and ZKP for private authentication. We offer computational proofs for important components together with a thorough security analysis utilizing formal verification tools like ProVerif and Tamarin Prover. Comparing our framework to other alternatives, the findings show that it provides stronger security guarantees, better privacy protection, and increased scalability. Our approach also defends against a broader variety of possible threats, such as man-inthe-middle attack, repudiation attacks, and side-channel attacks. This work opens the door for more effective and patient-cantered healthcare information systems by advancing secure and privacy-preserving EHR management.
Traditional finance and crypto aren't just different systems-they're different paradigms speaking different languages. Traditional banks measure processes in days, compliance in paperwork, and access in restrictions. Cryptocurrency platforms promise instant transactions but often at the cost of compliance frameworks that traditional institutions require. These systemic limitations in both traditional and cryptocurrency systems highlight the critical need for a unified approach. Using STORE's decentralized cloud computing protocol as an example, this paper emphasizes a different future as it demonstrates the feasibility and impact of automated compliance through the transformative CLEAR framework. Our dual-database architecture achieves authenticated regulatory compliance at global scale, with our implementation achieving 55.6 seconds (verified) for complete end-to-end transactions, with KYC verification (18.84s), document processing (14.24s), and payment settlement (6.55s). This transforms what traditional finance considers a weeks-long journey into a seconds-long verification, without compromising the compliance standards that make global finance possible. It's not just faster-it's fundamentally re-imagined.
Cybersecurity has encountered significant challenges, including identity theft, data breaches, and evolving threats to cyberspace. The decentralized, immutable, and transparent characteristics of blockchain technology have significantly enhanced its efficacy in bolstering cybersecurity. The application of blockchain in identity management, data privacy, and threat mitigation is examined, indicating it as a technology that addresses vulnerabilities inherent in conventional systems. Their capacity to enhance security, user autonomy, and trust is evidenced by decentralized Digital Identities (DIDs), smart contract-enforced data utilization policies, and blockchain-based threat intelligence systems. Despite its robustness, blockchain faces challenges, including scalability, interoperability, regulatory compliance, and energy consumption. Emerging trends (blockchain integration with AI and ML, quantum-resistant cryptography, etc.) are moving toward innovative solutions to these issues. Furthermore, the overlap of blockchain with zero-trust architectures highlights the utility of blockchain in present-day cybersecurity frameworks. The use of blockchain in finance is emphasized through this study as a demand for industry collaboration, scalable innovations, and a supportive regulatory framework to unleash the potential of the blockchain. A blockchain solution can help fill existing gaps in security strategies and pave the way to adoptive security.
This study aims to address the challenges and propose solutions for the Optimization of Blockchain-Based Cybersecurity Systems to Enhance Resilience Against Ransomware Attacks using a Systematic Literature Review (SLR) approach. Blockchain is increasingly recognized as a transformative technology in cybersecurity due to its decentralized structure, transparency, and robustness in securing data. Despite these advantages, its widespread adoption is hindered by several challenges, including scalability, interoperability, high energy consumption, and limited access to representative ransomware datasets. This research highlights that integrating blockchain with advanced technologies such as data analytics, machine learning, and Explainable AI (XAI) can significantly enhance its effectiveness in combating ransomware.The findings reveal that Graph Convolutional Neural Networks (GCN) enable real-time detection of ransomware patterns in network traffic with an accuracy of up to 95%. Furthermore, Layer-2 solutions like the Lightning Network and sharding effectively alleviate the load on main blockchains, thereby increasing transaction throughput. Efficient consensus mechanisms, including Proof of Stake (PoS) and Delegated Proof of Stake (DPoS), address energy consumption issues, making blockchain more adaptable to IoT and resource-constrained environments. These approaches have proven successful in enabling early detection, mitigation, and prevention of ransomware in IoT systems, cloud infrastructures, and smart grid networks. The implications of this study underscore the potential of blockchain as a critical component of proactive and adaptive cybersecurity systems. However, overcoming existing challenges requires further development of hybrid frameworks that integrate blockchain with data analytics and machine learning technologies. In addition, efforts should focus on standardizing global security protocols to enhance interoperability and creating robust, diverse ransomware datasets to support more accurate detection systems. Future research should also explore methods to minimize latency and improve blockchain efficiency in real-time cybersecurity applications.
Prof. R. C. Pachhade, Shubham Gaikwad, Aditya Sawwase, Dahihande Rohan
The idea focuses on enhancing the security and reliability of data exchange between military units. Traditional methods of secure communication often involve centralized systems, which can be vulnerable to breaches and single points of failure. By utilizing blockchain technology, the implementing idea introduces a decentralized approach that ensures data integrity and security through a distributed ledger system. In this system, blockchain provides a tamper-proof record of all communications, ensuring that data is encrypted, verified, and resistant to unauthorized access. This decentralized model eliminates the need for a central authority, reducing potential vulnerabilities and increasing the resilience of the communication network. As a result, the system aims to offer a more secure, reliable, and robust solution for confidential data transmission between army stations, enhancing operational security and efficiency.
Growing worries about data security and privacy are driving the development of privacy-enhancing technologies (PETs) like secure multiparty computation (MPC) and zero-knowledge (ZK) proofs. These technologies offer strong theoretical guarantees for protecting sensitive data while still allowing its use. Critical sectors like finance and healthcare are increasingly adopting PETs, facilitated by complex PET systems designed for secure and efficient implementation. However, despite the theoretical strengths of PETs, the intricate nature of these systems can create practical vulnerabilities. Severe incidents have already caused significant financial losses and eroded trust. This thesis tackles these reliability concerns by systematically testing modern PET systems. The first work in this thesis uncovers logic bugs in secure multiparty computation (MPC) compilers. These compilers automatically transform high-level MPC programs, written in domain-specific languages (DSLs), into low-level MPC executables. We introduce MT-MPC, a metamorphic testing (MT) framework, to test MPC compilers using three tailored metamorphic relations (MRs). Despite the high engineering quality of MPC compilers, MT-MPC finds 13 bugs in leading compilers, which compromises the dependability of MPC systems. The second work focuses on the correctness and security of zero-knowledge (ZK) compilers, which compile ZK DSL programs into ZK circuits. We propose MTZK, a MT framework that uncovers logic bugs in ZK compilers. These bugs can allow attackers to generate false ZK proofs that ZK verifiers unexpectedly accept, leading to security breaches and financial losses. MTZK uses two carefully designed MRs to deliver effective test cases for ZK compilers. Evaluation of four industrial ZK compilers reveals 21 bugs. We also demonstrate the severe security implications of these bugs through potential exploits. The third work unveils a new class of vulnerabilities in PET-enhanced machine learning (ML) models. We present ConPETro, the first attack on PET-enhanced ML models with maliciously crafted configurations. These configurations cause PET-enhanced models to behave similarly to plaintext models under normal inputs, but exhibit significantly reduced robustness under trigger-embedded inputs. ConPETro achieves an average maximum attack success rate of 65.6% while maintaining merely 4% of accuracy drop on normal inputs. We also show that such attacks are highly stealthy and can hardly be detected or defended by traditional mechanisms.
Open access
Information and Cyber Security
Transportation Systems and Safety
Physical Unclonable Functions (PUFs) and Hardware Security
Decentralized Finance (DeFi) protocols face significant security challenges, with over $500 million lost to exploits in 2024. While technical vulnerabilities are well-studied, the security implications of novel governance mechanisms remain underexplored, particularly for protocols using competitive dynamics rather than traditional voting. This thesis presents the first comprehensive security analysis of the Foresight Protocol, a DeFi system that optimizes reserve composition through competitive game-theoretic mechanisms. The research adapts traditional threat modeling for blockchain by extending STRIDE with three DeFispecific categories: Governance Vulnerabilities (G), Parameter Interaction Vulnerabilities (P), and Systemic Risks (SR). The analysis reveals that Foresight’s economic design effectively eliminates traditional attack vectors including flash loans, MEV exploitation, and bank runs through stake requirements and extended evaluation periods. However, critical vulnerabilities emerge from the protocol’s governance complexity. The reliance on decentralized decision-making introduces social and educational requirements that actors could exploit through identity spoofing, economic bribery, or information asymmetries. Additionally, the mathematical sophistication of competition parameters creates opportunities for manipulation disguised as optimization, while distinguishing genuine value from market manipulation remains an inherent challenge. Key findings indicate that while economic incentives can provide robust security, governance mechanisms introduce attack surfaces just as significant as technical vulnerabilities. The extended threat modeling framework offers a reusable methodology for analyzing innovative DeFi protocols. The research demonstrates that next-generation DeFi protocols can achieve security through economic design, but success requires sophisticated community capabilities and ongoing empirical validation. This work emphasizes the importance of threat modeling starting from the design phase to ensure comprehensive security in novel DeFi systems.
Open access
Blockchain Technology Applications and Security
Information and Cyber Security
Infrastructure Resilience and Vulnerability Analysis
The article examines the evolution of the concept of Integrated Information Security Systems (IISS) in the context of the digital transformation of the public sector, modernization of the national cybersecurity framework, and harmonization of Ukrainian legislation with international information security standards. The study reveals the relationship between classical approaches to building IISS – based on mandatory certification of technical protection complexes – and the modern paradigm of risk-oriented security management introduced by the new Law of Ukraine No. 4336-IX “On Amendments to Certain Laws of Ukraine on the Protection of Information and Cybersecurity of State Information Resources and Critical Information Infrastructure Objects.” The research emphasizes the shift from a formal certification model to a process-oriented approach based on security profiles, risk management, continuous monitoring, and security auditing. Special attention is devoted to analyzing the potential of blockchain technologies in enhancing the resilience of state information systems against cyberattacks, insider threats, and unauthorized data modifications. The study substantiates the feasibility of using distributed ledgers to ensure the immutability, authenticity, transparency, and accountability of information processes. It is determined that blockchain can serve as an innovative component of the modern IISS architecture, complementing cryptographic protection mechanisms, access control, user activity auditing, and event monitoring. A conceptual model of blockchain integration into the traditional structure of IISS is proposed, forming a new trust ecosystem within state information resources. The combination of technological innovation with the legal requirements of Law No. 4336-IX creates a foundation for improving the effectiveness of the national cybersecurity system. The purpose of the study is to substantiate the scientific, methodological, and technological directions for the modernization of Ukraine’s Integrated Information Security Systems through the integration of blockchain technologies in protecting state information resources in accordance with current legislation and international standards ISO/IEC 27001, ISO/IEC 27701, and GDPR.
This paper introduces a novel framework for Zero-Knowledge Infrastructure Verification (ZKIV) that combines chaos engineering principles with security operations and zero-knowledge proofs to create a robust infrastructure verification system. By leveraging these technologies within a DevOps context, organizations can validate the integrity and security posture of their infrastructure without revealing sensitive configuration details or credentials. This approach, which we term ChaosSecOps, represents a significant advancement in infrastructure security verification, enabling teams to verify compliance, detect misconfigurations, and identify vulnerabilities without exposing sensitive information. Through a detailed AWS implementation case study, this paper demonstrates how ZKIV can be applied to modern cloud environments to enhance security, streamline compliance verification, and build resilient systems.Executive SummaryThis paper introduces Zero-Knowledge Infrastructure Verification (ZKIV), a novel framework for validating the security and compliance of complex, modern infrastructure (particularly cloud environments like AWS) without exposing sensitive configuration details or credentials. ZKIV achieves this by combining principles from:• Zero-Knowledge Proofs (ZKPs): While full cryptographic ZKPs are discussed, the paper focuses on "functional zero-knowledge" approaches practical for infrastructure. This means proving that security controls are in place and functioning correctly without revealing the underlying configurations themselves. Examples include black-box testing, output-only verification, and attestation.• Chaos Engineering: The deliberate introduction of controlled failures (like misconfigurations or simulated attacks) to test system resilience and the effectiveness of security controls.• Security Operations (SecOps): Continuous monitoring, threat response, and security automation practices.• DevOps: Leveraging automation, continuous integration/continuous delivery (CI/CD), and Infrastructure as Code (IaC). The integration of these disciplines is termed ChaosSecOps. Key Benefits of ZKIV• Enhanced Security: Verification happens without needing to expose sensitive data, reducing the attack surface.• Improved Compliance: Continuous, automated verification ensures ongoing adherence to regulatory and internal security policies (e.g., PCI DSS, SOC 2). Evidence is collected in a zero-knowledge manner.• Reduced Operation Risk: Proactive identification of vulnerabilities and misconfigurations before they can be exploited.• Increased Confidence: Greater assurance in the security posture due to systematic and continuous testing.• Scalability: Verification is automated and can be used across many systems.• Efficiency: Verification can be done faster.ZKIV Framework ComponentsThe framework consists of several key components that work together:• Verification Orchestrator: The central control point for scheduling, executing, and managing verification tests.• Policy Engine: Defines and enforces security and compliance rules (using policy-as-code).• Test Agents: Ephemeral (short-lived) components deployed within the infrastructure to perform black-box testing.• Evidence Collection System: Gathers test results in a way that preserves zero-knowledge (no sensitive data revealed).• Remediation Framework: Automates the fixing of identified security issues.AWS Implementation Case StudyA detailed case study demonstrates ZKIV implementation within a financial services organization using AWS. Key AWS services used include AWS Organizations, Security Hub, Lambda, Step Functions, EventBridge, Systems Manager, S3, and Config. The case study shows practical application of zero-knowledge techniques like:• Least-Privilege IAM Roles: Verification agents have only the permissions needed to check configurations, not to access the data they protect.• Output-Only Verification: Validating database security settings without querying the database itself.• Black-Box Network Testing: Using isolated containers to test network segmentation without accessing internal network configurations.
Cryptocurrency exchange hacks remain a persistent threat, posing significant financial and security risks.The 2025 Bybit hack, resulting in approximately $1.4 billion in losses, is the largest cryptocurrency heist to date, highlighting the vulnerabilities even among leading exchanges.This paper examines the implications of such breaches on market stability, regulatory policies, and investor confidence, particularly within the context of the Trump administration's deregulatory approach to digital assets.The analysis explores the trade-offs between promoting innovation and ensuring robust security frameworks, emphasizing the potential for policy adjustments in light of escalating cyber threats.Additionally, the study reviews historical exchange hacks, demonstrating a pattern of increasing sophistication among malicious actors.The findings suggest that regulatory clarity and enhanced security measures are essential for the long-term stability of the cryptocurrency ecosystem.Future research directions include evaluating global regulatory responses, the role of decentralized exchanges, and the effectiveness of cybersecurity protocols.
<p><strong>This paper contributes to the literature by</strong> presenting a reproducible framework for designing and testing fair on-chain governance systems. It introduces <em>CryptoKen</em>, an Ethereum-based token using quadratic voting to reduce plutocracy and enhance participation in decentralized organizations, achieving high usability (SUS 82.5) and 92% verified test coverage.</p>
Zubaida Rehman, Iqbal Gondal, Hai Dong, Mengmeng Ge · 6 authors
Eclipse attacks, which isolate victim nodes by monopolizing their peer connections, remain a critical threat to Ethereum’s consensus mechanism. To address this, we present a principled framework for detecting Eclipse attacks in Ethereum peer-to-peer networks, grounded in a formal adversarial model. Existing defenses are either ad-hoc or lack provable guarantees, leaving open questions about their reliability under adaptive adversaries. Our work aims to bridge this gap by formally defining eclipse attack detection as a security property. We specify soundness, completeness, and robustness theorems under bounded adversarial drift, and derive formal guarantees within false positive and false negative bounds, resilience to adversarial manipulation, and multi-node compositional reliability. We then instantiate a lightweight detection framework that maps packet-level traffic features to predictions using ensemble classifiers (Random Forest, XGBoost). The system was validated using a controlled Ethereum testbed and extended with CTGAN-generated synthetic traces to emulate networks of up to 100 nodes. Empirical evaluation shows that our framework achieves up to 96% F1-score with sub-second inference latency, well within Ethereum’s 12-second Proof-of-Stake validator time slots. These findings demonstrate that lightweight statistical features, when coupled with formal analysis, enable accurate, efficient, and scalable detection of network-level partitioning attacks. Our work establishes a deployable and theoretically grounded defense foundation for securing modern blockchain systems against eclipse adversaries.
This study evaluates the effectiveness of cybersecurity frameworks in mitigating cyber threats in traditional banking while assessing their applicability to Decentralized Finance (DeFi). Using financial sector reports, cybersecurity incident databases, and DeFi security audits, we analyze compliance with NIST CSF, ISO/IEC 27001, and PCI-DSS alongside factors such as bank size, IT security investments, and regulatory fines to determine their impact on cyber resilience. Logistic regression results indicate that compliance with cybersecurity frameworks reduces cyberattack likelihood (p = 0.0689, marginally significant), while larger institutions face fewer threats (p = 0.0256, statistically significant). However, increased IT security budgets paradoxically correlate with higher attack frequencies (p = 0.0385, statistically significant), suggesting larger attack surfaces may offset security investments. In contrast, DeFi faces disproportionately higher smart contract exploits, flash loan attacks, and oracle manipulation, leading to significantly greater financial losses (F = 216.92, p < 0.001, highly significant) than traditional banking cyber incidents. Regulatory compliance and industry collaboration show promise in reducing attack occurrences, with cyber incidents projected to decline by over 40% by 2029 under stricter enforcement. However, traditional frameworks are insufficient for DeFi’s decentralized structure, necessitating AI-driven threat detection, mandatory smart contract audits, secure oracle mechanisms, and adaptive regulatory frameworks. This study highlights the urgent need for tailored DeFi cybersecurity strategies while reinforcing the effectiveness of compliance-driven models in banking. It provides actionable insights for financial institutions, regulators, and cybersecurity professionals seeking to enhance resilience across centralized and decentralized financial systems.
The paper presents the main approaches to the construction of the PKI public key architecture divided into basic, two-level, and multi-level hierarchies. Modern methods of attacks on existing public key infrastructures, protocols for building secure connections of both wired and wireless systems are considered. The basics of the class of attacks on PKI infrastructures are defined, of which the main attention is paid to the most dangerous class of attacks – man-in-the-middle (MITM-attacks). The paper provides models of various classes of MITM attacks, their details and existing methods of reducing the risks of their implementation. Existing examples of successful attacks on enterprises and various organizations that implemented MITM attack models at the application, network, and physical levels of the network interaction model are also given. For the PKI infrastructure, one of the options is its segmentation, which allows to reduce the scope of attacks on the key certification center. The paper also provides an alternative way to protect against MITM attacks using distributed micro ledger technology (DLT) to create a decentralized cryptographic key distribution system (DKMS). The solution is based on the use of micro ledgers (distributed ledger technology – DMLT). Using DMLT to create a DKMS allows protection against additional classes of MITM attacks.
The integration of blockchain technology into automated incident management systems represents a significant advancement in securing and validating system logs and incident records. This article presents a comprehensive article analysis of blockchain's application in incident management, examining its role in creating immutable audit trails and enhancing security controls. Through systematic review of implementation patterns and industry case studies, the article explores how distributed ledger technology addresses traditional challenges in log integrity and incident response validation. The article investigates the architectural frameworks necessary for successful blockchain integration, including considerations for scalability, performance, and regulatory compliance. The findings demonstrate that blockchain-based incident management systems offer enhanced transparency, improved audit capabilities, and robust security measures compared to traditional approaches. Additionally, the article examines emerging patterns in enterprise adoption, implementation challenges, and the synergies between blockchain and other emerging technologies in the incident management landscape. This article contributes to the growing body of knowledge on blockchain applications in enterprise security operations and provides a framework for organizations considering blockchain adoption for their incident management processes. The article concludes with recommendations for implementation and identifies areas for future research in this rapidly evolving field.
Clement Daah, Amna Qureshi, Irfan Awan, Savas Konur
The financial sector is increasingly facing advanced cyber threats, necessitating a shift from traditional security measures to more dynamic frameworks. This study presents a novel integration of Zero Trust architecture with hybrid access control system and blockchain technology to enhance security in financial institutions. Zero Trust enforces continuous authentication and dynamic access controls, while blockchain secures digital identities and transaction logs through its immutable ledger, ensuring data integrity and non-repudiation. The proposed framework, evaluated using OMNeT++ simulations enhanced by Ethereum-Ganache, shows improved detection accuracy, reduced false positives, and increased resistance to insider threats and other attacks. It also strengthens compliance with regulatory requirements through robust audit trails, providing enhanced protection for sensitive financial data.
André Augusto, Rafael Belchior, Jonas Pfannschmidt, André Vasconcelos · 5 authors
Cross-chain bridges are a type of middleware for blockchain interoperability that supports the transfer of assets and data across blockchains. However, several of these bridges have vulnerabilities that have caused 3.2 billion dollars in losses since May 2021. Some studies have revealed the existence of these vulnerabilities, but there is little quantitative research available, and there are no safeguard mechanisms to protect bridges from such attacks. Furthermore, no studies are available on the practices of cross-chain bridges that can cause financial losses. We propose \toolName~(Cross-Chain Watcher), a modular and extensible logic-driven anomaly detector for cross-chain bridges. It operates in three main phases: (1) decoding events and transactions from multiple blockchains, (2) building logic relations from the extracted data, and (3) evaluating these relations against a set of detection rules. Using \toolName, we analyze data from two previously attacked bridges: the Ronin and Nomad bridges. \toolName~was able to successfully identify the transactions that led to losses of \$611M and \$190M (USD) and surpassed the results obtained by a reputable security firm in the latter. We not only uncover successful attacks, but also reveal other anomalies, such as 37 cross-chain transactions (\CCTX) that these bridges should not have accepted, failed attempts to exploit Nomad, over \$7.8M worth of tokens locked on one chain but never released on Ethereum, and \$200K lost by users due to inadequate interaction with bridges. We provide the first open dataset of 81,000 \CCTXS~across three blockchains, capturing more than \$4.2B in token transfers.