This article defines and exemplifies the primary information security goals when organisations use, operate or develop blockchain technology solutions. The proposed goals extend the well-known CIA-triad Confidentiality, integrity, Availability) to account for the increased complexity in securing software solutions and organisations. The understanding of these goals can help information security practitioners design and implement more effective security controls for protecting blockchain solutions and organisations. Non-security professionals in the blockchain field can also benefit from the concepts in this article, as security is a core component in all blockchains.
Cloud-hosted applications are prone to targeted attacks such as DDoS, advanced persistent threats, cryptojacking which threaten service availability. Recently, methods for threat information sharing and defense require co-operation and trust between multiple domains/entities. There is a need for mechanisms that establish distributed trust to allow for such a collective defense. In this paper, we present a novel threat intelligence sharing and defense system, namely âDefenseChainâ, to allow organizations to have incentive-based and trustworthy co-operation to mitigate the impact of cyber attacks. Our solution approach features a consortium Blockchain platform to obtain threat data and select suitable peers to help with attack detection and mitigation. We propose an economic model for creation and sustenance of the consortium with peers through a reputation estimation scheme that uses âQuality of Detectionâ and âQuality of Mitigationâ metrics. Our evaluation experiments with DefenseChain implementation are performed on an Open Cloud testbed with Hyperledger Composer and in a simulation environment. Our results show that the DefenseChain system overall performs better than state-of-the-art decision making schemes in choosing the most appropriate detector and mitigator peers. In addition, we show that our DefenseChain achieves better performance trade-offs in terms of metrics such as detection time, mitigation time and attack reoccurence rate. Lastly, our validation results demonstrate that our DefenseChain can effectively identify rational/irrational service providers.
Alexandra Mai, Katharina Pfeffer, Matthias Gusenbauer, Edgar Weippl · 5 authors
Frequent reports of monetary loss, fraud, and user-caused security incidents in the context of cryptocurrencies emphasize the need for human-centered research in this domain. We contribute the first qualitative user study (N=29) on user mental models of cryptocurrency systems and the associated threat landscape. Using Grounded Theory, we reveal misconceptions affecting users' security and privacy. Our results suggest that current cryptocurrency tools (e.g., wallets and exchanges) are not capable of counteracting threats caused by these misconceptions. Hence, users frequently fail to securely manage their private keys or assume to be anonymous when they are not. Based on our findings, we contribute actionable advice, grounded in the mental models of users, to improve the usability and secure usage of cryptocurrency systems.
Computer security incident response teams typically rely on threat intelligence platforms for information about sightings of cyber threat events and indicators of compromise. Other security building blocks, such as Network Intrusion Detection Systems, can leverage the information to prevent malicious adversaries from spreading malware across critical infrastructures. The effectiveness of threat intelligence platforms heavily depends on the willingness to share among organizations and the responsible use of sensitive information that may potentially harm the reputation of the reporting organization. The challenge that we address is the lack of trust in the source providing the threat intelligence and the information itself. We enhance our security framework TATISâoffering fine-grained protection for threat intelligence platform APIsâwith distributed ledger capabilities to enable reliable and trustworthy threat intelligence sharing with the ability to audit the provenance of threat intelligence. We have implemented and evaluated the feasibility of our distributed framework on top of the Malware Information Sharing Platform (MISP) solution, and we evaluate the performance impact using real-world open-source threat intelligence feeds.
In recent years, cryptocurrencies have increasingly gained interest. The underlying technology, Blockchain, shifts the responsibility for securing assets to the end-user and requires them to manage their (private) keys. Little attention has been given to how cryptocurrency users handle the challenges of key management in practice and how they select the tools to do so. To close this gap, we conducted semi-structured interviews (N=10). Our thematic analysis revealed prominent themes surrounding motivation, risk assessment, and coin management tool usage in practice. We found that the choice of tools is driven by how users assess and balance the key risks that can lead to loss: the risk of (1) human error, (2) betrayal, and (3) malicious attacks. We derive a model, explaining how risk assessment and intended usage drive the decision which tools to use. Our work is complemented by discussing design implications for building systems for the crypto economy.
With rise of cryptocurrency popularity and value, more and more cybercriminals seek to profit using that new technology. Most common ways to obtain illegitimate profit using cryptocurrencies are ransomware and cryptojacking also known as malicious mining. And while ransomware is well-known and well-studied threat which is obvious by design, cryptojacking is often neglected because it's less harmful and much harder to detect. This article considers question of cryptojacking detection. Brief history and definition of cryptojacking are described as well as reasons for designing custom detection technique. We also propose complex detection technique based on CPU load by an application, which can be applied to both browser-based and executable-type cryptojacking samples. Prototype detection program based on our technique was designed using decision tree algorithm. The program was tested in a controlled virtual machine environment and achieved 82% success rate against selected number of cryptojacking samples. Finally, we'll discuss generalization of proposed technique for future work.
Vyper has been proposed as a new high-level language for Ethereum smart\ncontract development due to numerous security vulnerabilities and attacks\nwitnessed on contracts written in Solidity since the system's inception. Vyper\naims to address these vulnerabilities by providing a language that focuses on\nsimplicity, auditability and security. We present a survey where we study how\nwell-known and commonly-encountered vulnerabilities in Solidity feature in\nVyper's development environment. We analyze all such vulnerabilities\nindividually and classify them into five groups based on their status in Vyper.\nTo the best of our knowledge, our survey is the first attempt to study security\nvulnerabilities in Vyper.\n
Critical infrastructure sectors are increasingly adopting enterprise Distributed Ledgers (DL) to host long-term assets, systems, and information that is considered vital to an organizationâs ability to operate without clear or public plans and strategies to migrate safely and timely to Post Quantum Cryptography (PQC). A quantum computer (QC) compromised DL would allow, eavesdropping, unauthorized client authentication, signed malware, cloak-in encrypted session, a man-in-the-middle attack (MITM), forged documents and emails. These attacks can lead to disruption of service, damage of reputation and trust, injury to human life, and the loss of intellectual property, assets, regulated data, and global economic security. In 2018, Gartner revealed that a QC is a digital disruption that organizations may not be ready and prepared, and CIOs may not see coming. On September 18, 2019, IBM announced the largest universal QC available for commercial use would be available in October 2019. On October 23, 2019, Google officially announced âQuantum Supremacy,â âby performing a calculation in 200 seconds that would take a classical supercomputer approximately 10,000 years.â DL Cyber Resilience requires âreasonableâ measures, policies, procedures, strategies, and risk management before large-scale deployment. Cyber Resilience implementations must be a critical component during the design and building phase, or during the initialization phase. The most significant existing attack vectors for enterprise DLs is the Public Key Infrastructure (PKI), which is fundamental in securing the Internet and enterprise DLs and is a core component of authentication, data confidentiality, and data and system integrity [1] [2]. Effectively implementing and managing a quantum-resistant PKI solution requires adherence to PKI standards, industry requirements, potential government mandates, certificate management policies, training personnel, and data recovery policies that currently do not exist. This research discusses security risks in enterprise DL PKI, areas that can be compromised, and provides an idea of what should be in a PKI DL Risk Management Framework plan.
The cutting-edge technologies are the main drivers of modern innovations. At the same time, they also bring new risks to security and privacy. In addition to the legal regulation of security measures in the digital world, it is now necessary to incorporate cyber security knowledge into curricula. Advanced technologies are introducing new security risks. The dynamic change in cyber security affects business risk management and is driven by the continuous improvement of sophisticated technology by malicious actors.The main focus of the study is to justify the need to integrate cyber security into curricula that are related to cutting-edge technologies. The emphasis is on the need for proactive steps in education to prepare learners to adequately address the cybersecurity issues that come with IoT (Internet of Things), AI (Artificial Intelligence), DLT (Distributed Ledger Technology), VR (Virtual Reality and Augmented Reality) and containers.The article provides an overview of the regulatory framework and security incidents that inevitably lead to conclusions about the need to introduce the problem area of cybersecurity in the curriculum for IoT, AI, DLT, VR and containers. Updating the curriculum with cyber security components will lead to the full realization of specialists in the respective field. The cyber security competences have been analyzed for the current state of the problem, taking into account both the regulatory requirements of Europe and some national ones.The analyzes, conclusions and recommendations of this article are aimed at reducing the deficits in cybersecurity training in problem areas that have progressed without compliance with standards or minimum requirements for protection against measured impacts. This is a step towards applying the EU's common competences for cybersecurity skills in the SME sector on the path to simultaneously promoting technical and organizational expertise and corporate culture to comply with emerging regulations, directives and laws related to cybersecurity and privacy.This article is aligned with the efforts of the EU Cybersecurity Competencies Team responding for the skills shortage on the labor market.In addition to the "shift left" in the software production process (SDLC), it also justifies the paradigm for the EARLY INCORPORATING shift in the curriculum.
Information security incident under-reporting is unambiguously a business problem, as identified by a variety of sources, such as ENISA (2012), Symantec (2016), Newman (2018) and more. This research project identified the underlying issues that cause this problem and proposed a solution, in the form of an innovative artefact, which confronts a number of these issues. This research project was conducted according to the requirements of the Design Science Research Methodology (DSRM) by Peffers et al (2007). The research question set at the beginning of this research project, probed the feasible formation of an incident reporting solution, which would increase the motivational level of users towards the reporting of incidents, by utilizing the positive features offered by existing solutions, on one hand, but also by providing added value to the users, on the other. The comprehensive literature review chapter set the stage, and identified the reasons for incident underreporting, while also evaluating the existing solutions and determining their advantages and disadvantages. The objectives of the proposed artefact were then set, and the artefact was designed and developed. The output of this development endeavour is âIRDAâ, the first decentralized incident reporting application (DApp), built on âQuorumâ, a permissioned blockchain implementation of Ethereum. Its effectiveness was demonstrated, when six organizations accepted to use the developed artefact and performed a series of pre-defined actions, in order to confirm the platformâs intended functionality. The platform was also evaluated using Venable et alâs (2012) evaluation framework for DSR projects. This research project contributes to knowledge in various ways. It investigates blockchain and incident reporting, two domains which have not been extensively examined and the available literature is rather limited. Furthermore, it also identifies, compares, and evaluates the conventional, reporting platforms, available, up to date. In line with previous findings (e.g Humphrey, 2017), it also confirms the lack of standard taxonomies for information security incidents. This work also contributes by creating a functional, practical artefact in the blockchain domain, a domain where, according to Taylor et al (2019), most studies are either experimental proposals, or theoretical concepts, with limited practicality in solving real-world problems. Through the evaluation activity, and by conducting a series of non-parametric significance tests, it also suggests that IRDA can potentially increase the motivational level of users towards the reporting of incidents. This thesis describes an original attempt in utilizing the newly emergent blockchain technology, and its inherent characteristics, for addressing those concerns which actively contribute to the business problem. To the best of the researcherâs knowledge, there is currently no other solution offering similar benefits to users/organizations for incident reporting purposes. Through the accomplishment of this projectâs pre-set objectives, the developed artefact provides a positive answer to the research question. The artefact, featuring increased anonymity, availability, immutability and transparency levels, as well as an overall lower cost, has the potential to increase the motivational level of organizations towards the reporting of incidents, thus improving the currently dismaying statistics of incident under-reporting. The structure of this document follows the flow of activities described in the DSRM by Peffers et al (2007), while also borrowing some elements out of the nominal structure of an empirical research process, including the literature review chapter, the description of the selected research methodology, as well as the âdiscussion and conclusionâ chapter.
As the value of technical information increases, hacking attacks are trying to steal technical information through hacking. Recently, hacking of cryptocurrency exchanges is much easier to monetize than existing technical information, making it a major attack target for hackers. In the case of technical information, it is required to seize the technical information and sell it to the black market for cashing.In the case of cryptocurrency, most hacking attacks are concentrated on cryptocurrency exchanges because it is easy to cash out and not easy to track when successful hacking. Although technology cannot be hacked, cryptocurrency transactions traded on cryptocurrency exchanges are not recorded on the blockchain which is simply internal exchanges, so insiders may manipulate the quotes and leave gaps or leak out. Therefore, this research analyzes the recent hacking attacks of cryptocurrency exchanges and proposes solutions to secure cryptocurrency trading.
Insufficient authentication and authorization of interconnected components are major risks in the Industrial Control System (ICS). To address this, we introduce CyRA, a realtime risk-based security assessment framework that consists of a Nested-ICS security architecture, secure registration protocol, and risk-based multi-factor authentication protocol by which every component is authenticated and authorized to ensure secure communications and prevent cyber attacks in the ICS. Our proposed framework applies Zero-Knowledge Proof of Knowledge (ZKPK) to perform risk-based multi-factor authentication and authorization using a digitally signed identity that encodes secrets provided by the component. Our approach is based on Threat Modeling (TM), Vulnerability Identification (VI), and Consequence Analysis (CA) to provide adequate and efficient authentication and authorization in the ICS. The resilience of our framework is evaluated against recent well-known cyber attacks. Specifically, we conduct a risk-based security assessment for a Safety Instrumentation System (SIS) communication protocol, known as TriStation. The results show that our framework enhances the security of the protocol in dealing with real-time uncertainty of threats, vulnerabilities, and consequences from a new cyber-attack, known as TRITON malware.
Traditional management practices applied to the cybersecurity realm are causing significant delays to the product release cycle for major organizations and government agencies. These delays are often seen as a necessary part of the security landscape to ensure appropriate approvals, audits, and risks are addressed prior to fielding software. However, the exact opposite outcome has been observed; delayed releases decrease overall security and functionality. This paper presents an alternative approval and review process using blockchain technology that complements agile development and continuous delivery paradigms. An example implementation is provided to demonstrate the behavior of the proposed system under hypothetical auditing and threat assessment scenarios.
Cryptocurrencies have garnered much attention in recent years, both from the academic community and industry. One interesting aspect of cryptocurrencies is their explicit consideration of incentives at the protocol level. Understanding how to incorporate this into the models used to design cryptocurrencies has motivated a large body of work, yet many open problems still exist and current systems rarely deal with incentive related problems well. This issue arises due to the gap between Cryptography and Distributed Systems security, which deals with traditional security problems that ignore the explicit consideration of incentives, and Game Theory, which deals best with situations involving incentives. With this work, we aim to offer a systematization of the work that relates to this problem, considering papers that blend Game Theory with Cryptography or Distributed systems and discussing how they can be related. This gives an overview of the available tools, and we look at their (potential) use in practice, in the context of existing blockchain based systems that have been proposed or implemented.
Sophisticated mass attacks, especially when exploiting zero-day vulnerabilities, have the potential to cause destructive damage to organizations and critical infrastructure. To timely detect and contain such attacks, collaboration among the defenders is critical. By correlating real-time detection information (alerts) from multiple sources (collaborative intrusion detection), defenders can detect attacks and take the appropriate defensive measures in time. However, although the technical tools to facilitate collaboration exist, real-world adoption of such collaborative security mechanisms is still underwhelming. This is largely due to a lack of trust and participation incentives for companies and organizations. This paper proposes TRIDEnT, a novel collaborative platform that aims to enable and incentivize parties to exchange network alert data, thus increasing their overall detection capabilities. TRIDEnT allows parties that may be in a competitive relationship, to selectively advertise, sell and acquire security alerts in the form of (near) real-time peer-to-peer streams. To validate the basic principles behind TRIDEnT, we present an intuitive game-theoretic model of alert sharing, that is of independent interest, and show that collaboration is bound to take place infinitely often. Furthermore, to demonstrate the feasibility of our approach, we instantiate our design in a decentralized manner using Ethereum smart contracts and provide a fully functional prototype.
Christian Killer, Bruno Rodrigues, Burkhard Stiller
A cooperative network defense is one approach to fend off large-scale Distributed Denial-of-Service (DDoS) attacks. In this regard, the Blockchain Signaling System (BloSS) is a multi-domain, blockchain-based, cooperative DDoS defense system, where each Autonomous System (AS) is taking part in the defense alliance. Each AS can exchange attack information about ongoing attacks via the Ethereum blockchain. However, the currently operational implementation of BloSS is not interactive or visualized, but the DDoS mitigation is automated. In realworld defense systems, a human cybersecurity analyst decides whether a DDoS threat should be mitigated or not. Thus, this work presents the design of a security management dashboard for BloSS, designed for interactive use by cyber security analysts.
This paper proposes a cybersecurity control framework for blockchain ecosystems, drawing from risks identified in the practitioner and academic literature. The framework identifies thirteen risks for blockchain implementations, ten common to other information systems and three risks specific to blockchains: centralization of computing power, transaction malleability, and flawed or malicious smart contracts. It also proposes controls to mitigate the risks identified; some were identified in the literature and some are new. Controls that apply to all types of information systems are adapted to the different components of the blockchain ecosystem.