Lampis Alevizos, VinhâThong Ta, Mahmoud Hashem Eiza
Abstract With the purpose of defending against lateral movement in today's borderless networks, zero trust architecture (ZTA) adoption is gaining momentum. With a fullâscale ZTA implementation, it is unlikely that adversaries will be able to spread through the network starting from a compromised endpoint. However, the already authenticated and authorized session of a compromised endpoint can be leveraged to carry out limited, though malicious, activities ultimately rendering the endpoints the Achilles heel of ZTA. To effectively detect such attacks, distributed collaborative intrusion detection systems with an attack scenarioâbased approach have been developed. Nonetheless, advanced persistent threats have demonstrated their ability to bypass this approach with a high success ratio. As a result, adversaries can pass undetected or potentially alter the detection logging mechanisms to achieve a stealthy presence. Recently, blockchain technology has demonstrated solid use cases in the cyber security domain. In this paper, motivated by the convergence of ZTA and blockchainâbased intrusion detection and prevention, we examine how ZTA can be augmented onto endpoints. Namely, we perform a stateâofâtheâart review of ZTA models, realâworld architectures with a focus on endpoints, and blockchainâbased intrusion detection systems. We discuss the potential of blockchain's immutability fortifying the detection process and identify open challenges as well as potential solutions and future directions.
<span>Signature-based collaborative intrusion detection system (CIDS) is highly depends on the reliability of nodes to provide IDS attack signatures. Each node in the network is responsible to provide new attack signature to be shared with other node. There are two problems exist in CIDS highlighted in this paper, first is to provide data consistency and second is to maintain trust among the nodes while sharing the attack signatures. Recently, researcher find that blockchain has a great potential to solve those problems. Consensus algorithm in blockchain is able to increase trusts among the node and allows data to be inserted from a single source of truth. In this paper, we are investigating three blockchain consensus algorithms: proof of work (PoW), proof of stake (PoS), and hybrid PoW-PoS chain-based consensus algorithm which are possibly to be implemented in CIDS. Finally, we design an extension of hybrid PoW-PoS chain-based consensus algorithm to fulfill the requirement. This extension we name it as proof of attack signature (PoAS).</span>
In blockchain, approved transactions, including illegal ones, cannot be modified unlike existing bank transactions. To prevent the damage caused by illegal transactions, rapid anomaly detection of transactions is required because transactions can be modified before approval. However, existing anomaly detection methods must process all transactions in blockchain, and the processing time is longer than the interval of each approval. In this paper, we propose a subgraph-based anomaly detection method to perform the detection using a part of the blockchain data. The proposed structure of the subgraph is suitable for graphics processing units (GPUs) to accelerate detection by using parallel processing. In an evaluation using real Bitcoin transaction data, when the number of targeted transactions was one hundred, the proposed method was 11.1x faster than an existing GPU-based method without lowering the detection accuracy.
The Domain Name System (DNS) plays a crucial role in the Internet. However, it is vulnerable to many attacks such as the cache poisoning attack and DDoS attack. Though some countermeasures have been proposed, they still have some limitations. In this paper, we propose B-DNS, a blockchain-based domain name system, which can provide a secure and efficient DNS service. B-DNS fills up two shortcomings of current blockchain-based DNS, namely computation-heavy Proof-of-Work (PoW) protocol and inefficient query, by building a Proof-of-Stake (PoS) consensus protocol and an index of domains. We propose a novel way to quantitatively compare the security of B-DNS and legacy DNS in terms of attack success rate, attack cost, and attack surface. Our experiments show that the probability of a successful attack on B-DNS is 1% of a successful attack on legacy DNS, the attack cost goes up a million times in B-DNS, and the attack surface of B-DNS is far smaller than that of legacy DNS. The query performance evaluation of B-DNS shows that B-DNS can achieve similar or even less query latency than state-of-the-art commercial DNS implementations.
O. Lutz, Huili Chen, Hossein Fereidooni, Christoph Sendner ¡ 7 authors
Ethereum smart contracts are automated decentralized applications on the blockchain that describe the terms of the agreement between buyers and sellers, reducing the need for trusted intermediaries and arbitration. However, the deployment of smart contracts introduces new attack vectors into the cryptocurrency systems. In particular, programming flaws in smart contracts can be and have already been exploited to gain enormous financial profits. It is thus an emerging yet crucial issue to detect vulnerabilities of different classes in contracts in an efficient manner. Existing machine learning-based vulnerability detection methods are limited and only inspect whether the smart contract is vulnerable, or train individual classifiers for each specific vulnerability, or demonstrate multi-class vulnerability detection without extensibility consideration. To overcome the scalability and generalization limitations of existing works, we propose ESCORT, the first Deep Neural Network (DNN)-based vulnerability detection framework for Ethereum smart contracts that support lightweight transfer learning on unseen security vulnerabilities, thus is extensible and generalizable. ESCORT leverages a multi-output NN architecture that consists of two parts: (i) A common feature extractor that learns the semantics of the input contract; (ii) Multiple branch structures where each branch learns a specific vulnerability type based on features obtained from the feature extractor. Experimental results show that ESCORT achieves an average F1-score of 95% on six vulnerability types and the detection time is 0.02 seconds per contract. When extended to new vulnerability types, ESCORT yields an average F1-score of 93%. To the best of our knowledge, ESCORT is the first framework that enables transfer learning on new vulnerability types with minimal modification of the DNN model architecture and re-training overhead.
Intrusion Detection System (IDS) is one of the most important approaches in cyber security to protect networks against both inner and outer threats. Apart from traditional networks, IDSs have been implemented in various emerging networks, such as mobile networks and Vehicle Ad hoc Networks (VANETs). However, a critical problem in IDSs is that the detection capacity is gradually decaying with the emergence of unknown attacks. It is necessary to constantly retrain IDSs with a more extensive database, but the security institutes usually lack the motivation to persistently update and maintain the database for public. Thus, in this paper, a lifetime learning framework is proposed for IDSs with a blockchain-based database (bc-DB). In the proposed framework, the blockchain-based database is multilaterally maintained by the security institutes and universities using Data Coins (DCoins) as the incentives. In addition, a Lifetime Learning IDS (LL-IDS) is further designed as the supplement of the bc-DB for common IDS users. For the LL-IDS, the Growing Hierarchical Self-Organizing Map with probabilistic relabeling (GHSOM-pr) having flexible and hierarchical architecture is employed as the classifier, which grows to make itself perfectly fit the changeable bc-DB. Security analysis and simulation experiments show that the proposed lifetime learning framework are both secure and effective in attacks detection.
Bin Wang, Han Liu, Chao Liu, Zhiqiang Yang ¡ 7 authors
Decentralized finance, i.e., DeFi, has become the most popular type of application on many public blockchains (e.g., Ethereum) in recent years. Compared to the traditional finance, DeFi allows customers to flexibly participate in diverse blockchain financial services (e.g., lending, borrowing, collateralizing, exchanging etc.) via smart contracts at a relatively low cost of trust. However, the open nature of DeFi inevitably introduces a large attack surface, which is a severe threat to the security of participants funds. In this paper, we proposed BLOCKEYE, a real-time attack detection system for DeFi projects on the Ethereum blockchain. Key capabilities provided by BLOCKEYE are twofold: (1) Potentially vulnerable DeFi projects are identified based on an automatic security analysis process, which performs symbolic reasoning on the data flow of important service states, e.g., asset price, and checks whether they can be externally manipulated. (2) Then, a transaction monitor is installed offchain for a vulnerable DeFi project. Transactions sent not only to that project but other associated projects as well are collected for further security analysis. A potential attack is flagged if a violation is detected on a critical invariant configured in BLOCKEYE, e.g., Benefit is achieved within a very short time and way much bigger than the cost. We applied BLOCKEYE in several popular DeFi projects and managed to discover potential security attacks that are unreported before. A video of BLOCKEYE is available at https://youtu.be/7DjsWBLdlQU.
The Internet of Things (IoT) has been revolutionizing this world by introducing exciting applications almost in all walks of daily life, such as healthcare, smart cities, smart environments, safety, remote sensing, and many more. This paper proposes a new framework based on the blockchain and deep learning model to provide more security for Android IoT devices. Moreover, our framework is capable to find the malware activities in a real-time environment. The proposed deep learning model analyzes various static and dynamic features extracted from thousands of feature of malware and benign apps that are already stored in blockchain distributed ledger. The multi-layer deep learning model makes decisions by analyzing the previous data and follow some steps. Firstly, it divides the malware feature into multiple level clusters. Secondly, it chooses a unique deep learning model for each malware feature set or cluster. Finally, it produces the decision by combining the results generated from all cluster levels. Furthermore, the decisions and multiple-level clustering data are stored in a blockchain that can be further used to train every specialized cluster for unique data distribution. Also, a customized smart contract is designed to detect deceptive applications through the blockchain framework. The smart contract verifies the malicious application both during the uploading and downloading process of Android apps on the network. Consequently, the proposed framework provides flexibility to features for run-time security regarding malware detection on heterogeneous IoT devices. Finally, the smart contract helps to approve or deny to uploading and downloading harmful Android applications.
Cryptocurrencies have emerged as a new form of digital money that has not escaped the eyes of cyber-attackers. Traditionally, they have been maliciously used as a medium of exchange for proceeds of crime in the cyber dark-market by cyber-criminals. However, cyber-criminals have devised an exploitative technique of directly acquiring cryptocurrencies from benign users' CPUs without their knowledge through a process called crypto mining. The presence of crypto mining activities in a network is often an indicator of compromise of illegal usage of network resources for crypto mining purposes. Crypto mining has had a financial toll on victims such as corporate networks and individual home users. This paper addresses the detection of crypto mining attacks in a generic network environment using dynamic network characteristics. It tackles an in-depth overview of crypto mining operational details and proposes a semi-supervised machine learning approach to detection using various crypto mining features derived from complex network characteristics. The results demonstrate that the integration of semi-supervised learning with complex network theory modeling is effective at detecting crypto mining activities in a network environment. Such an approach is helpful during security mitigation by network security administrators and law enforcement agencies.
Network topology is one of the major factors in defining the behavior of a network. In the present scenario, the demand for network security has increased due to an increase in the possibility of attacks by malicious users. In this paper, a blockchain-based system is suggested for securely discovering and storing networks. Techniques such as cloud-based storage systems are not efficient and are lacking in trust, privacy, security, and data control. The blockchain-based technique suggested in this paper is capable of resolving these challenges. Experiments were performed using Mininet, Cisco Packet Tracer, and Ethereum blockchain with the network inference algorithm. This algorithm is capable of inferring the network topology even when only partial information regarding the network is available. The results obtained clearly show that the network is resistant to malicious users and various external attacks, making the network robust.
In the current work we discuss the notion of gateways as a means for interoperability across different blockchain systems. We discuss two key principles for the design of gateway nodes and scalable gateway protocols, namely (i) the opaque ledgers principle as the analogue of the autonomous systems principle in IP datagram routing, and (ii) the externalization of value principle as the analogue of the end-to-end principle in the Internet architecture. We illustrate the need for a standard gateway protocol by describing a unidirectional asset movement protocol between two peer gateways, under the strict condition of both blockchains being private/permissioned with their ledgers inaccessible to external entities. Several aspects of gateways and the gateway protocol is discussed, including gateway identities, gateway certificates and certificate hierarchies, passive locking transactions by gateways, and the potential use of delegated hash-locks to expand the functionality of gateways.
As the next-generation network architecture, software-defined networking (SDN) has great potential. But how to forward data packets safely is a big challenge today. In SDN, packets are transferred according to flow rules which are made and delivered by the controller. Once flow rules are modified, the packets might be redirected or dropped. According to related research, we believe that the key to forward data flows safely is keeping the consistency of flow rules. However, existing solutions place little emphasis on the safety of flow rules. After summarizing the shortcomings of the existing solutions, we propose FRChain to ensure the security of SDN data forwarding. FRChain is a novel scheme that uses blockchain to secure flow rules in SDN and to detect compromised nodes in the network when the proportion of malicious nodes is less than one-third. The scheme places the flow strategies into blockchain in form of transactions. Once an unmatched flow rule is detected, the system will issue the problem by initiating a vote and possible attacks will be deduced based on the results. To simulate the scheme, we utilize BigchainDB, which has good performance in data processing, to handle transactions. The experimental results show that the scheme is feasible, and the additional overhead for network performance and system performance is less than similar solutions. Overall, FRChain can detect suspicious behaviors and deduce malicious nodes to keep the consistency of flow rules in SDN.
Cryptocurrencies have enhanced financial transactions, but being decentralized, they pose numerous security threats to their users, warranting new anomaly detection systems for fraud prevention.The present research focuses on the machine learning (ML) techniques used in detecting suspicious activities in cryptocurrency networks, focusing on their contribution to AML and CFT compliance.The paper also compares supervised and unsupervised learning techniques and their merits and demerits.The supervised learning techniques, including Decision Trees, SVMs, and Neural Networks, are presented for their accuracy and flexibility, and, on the other hand, the unsupervised learning approaches, including Clustering, Isolation Forests, and Autoencoders are considered for their potential to discover new fraud patterns even if the training data is not labeled.An analysis of the use of explainability tools such as LIME and SHAP in artificial intelligence systems is also carried out to improve how users understand the results given to them by the AI models.These models have their real-life application illustrated by case studies, which prove helpful in identifying anomalies in Bitcoin and Ethereum transactions.New research directions suggest improvements in machine learning methods, the connection of the results with analysis tools based on blockchain, and cooperation with relevant authorities to improve the identification of threats and conformity with established guidelines.The potential of applying the idea of this work in traditional finance and cybersecurity is discussed, highlighting the possibility of applying ML in multiple fields to enhance security and compliance.The study then informs the significance of continued research and collaboration among disciplines to combat the emerging issues of financial fraud and cybercrimes related to cryptocurrencies.
Distributed Denial of Service (DDoS) attack is a major threat impeding service to legitimate requests on any network. Although the first DDoS attack was reported in 1996, the complexity and sophistication of these attacks has been ever increasing. A 2 TBps attack was reported in mid-August 2020 directed towards critical infrastructure, such as finance, amidst the COVID-19 pandemic. It is estimated that these attacks will double, reaching over 15 million, in the next 2 years. A number of mitigation schemes have been designed and developed since its inception but the increasing complexity demands advanced solutions based on emerging technologies. Blockchain has emerged as a promising and viable technology for DDoS mitigation. The inherent and fundamental characteristics of blockchain such as decentralization, internal and external trustless attitude, immutability, integrity, anonymity and verifiability have proven to be strong candidates, in tackling this deadly cyber threat. This survey discusses different approaches for DDoS mitigation using blockchain in varied domains to date. The paper aims at providing a comprehensive review, highlighting all necessary details, strengths, challenges and limitations of different approaches. It is intended to serve as a single platform to understand the mechanics of current approaches to enhance research and development in the DDoS mitigation domain.
Abstract By providing ubiquitous connectivity, effective data analytics tools, and better decision support systems for improved market competitiveness, the industrial internet of things (IIoT) promises creative business models in different industrial domains. However, the conventional IIoT architecture can no longer provide adequate support for such an enormous device as the number of nodes, and network size increases. Therefore, several challenges, such as security, privacy, centralization, trust, and integrity prevents faster adaptation of IIoT applications. To address aforementioned challenges, we present a deep blockchainâbased trustworthy privacyâpreserving secured framework (DBTP2SF) for IIoT environment. This framework comprises of three modules, namely, trust management module, a twoâlevel privacyâpreservation module, and an anomaly detection module. In trustworthiness module, blockchain (BC)âbased address reputation system is proposed. In the twoâlevel privacy module a BCâbased enhanced proof of work technique is simultaneously applied with AutoEncoder, to transform cyberâphysical system data into a new reduced form that prevents inference and poisoning attacks. In the anomaly detection module, deep neural network is deployed. Finally, due to various limitations of current CloudâFog infrastructure, we present a BCâinterplanetary file systems integrated CloudâFog architecture, namely, BlockCloud and BlockFog to deploy proposed DBTP2SF framework in IIoT environment. The experiment is conducted using IIoTâbased realistic dataset, namely, ToNâIoT. The performance analysis shows that the proposed approach outperforms using transformed dataset over peer privacyâpreserving intrusion detection strategies, and has obtained accuracy of 98.97%, and detection rate of 93.87%. Finally, we have shown the superiority of DBTP2SF framework over some of the recent stateâofâart techniques in both nonâBC and BCâbased IIoT system.
Blockchain technology is rapidly changing the transaction behavior and efficiency of businesses in recent years. Data privacy and system reliability are critical issues that is highly required to be addressed in Blockchain environments. However, anomaly intrusion poses a significant threat to a Blockchain, and therefore, it is proposed in this article a collaborative clustering-characteristic-based data fusion approach for intrusion detection in a Blockchain-based system, where a mathematical model of data fusion is designed and an AI model is used to train and analyze data clusters in Blockchain networks. The abnormal characteristics in a Blockchain data set are identified, a weighted combination is carried out, and the weighted coefficients among several nodes are obtained after multiple rounds of mutual competition among clustering nodes. When the weighted coefficient and a similarity matching relationship follow a standard pattern, an abnormal intrusion behavior is accurately and collaboratively detected. Experimental results show that the proposed algorithm has high recognition accuracy and promising performance in the real-time detection of attacks in a Blockchain.
Aiming at ensure the security and self-control of heterogeneous alliance network, this paper proposes a novel structure of identity authentication based on domestic commercial cryptography with blockchain in the heterogeneous alliance network. The domestic commercial cryptography, such as SM2, SM3, SM4, SM9 and ZUC, is adopted to solve the encryption, decryption, signature and verification of blockchain, whose key steps of data layer are solved by using domestic commercial cryptographic algorithms. In addition, it is the distributed way to produce the public key and private key for the security of the keys. Therefore, the cross domain identity authentication in the heterogeneous alliance network can be executed safely and effectively.
Electronic voting systems have several necessarily requirements, such as anonymity that others cannot link voters with votes, the fairness that votes should not be leaked before the tally, and the accuracy that eligible voters' votes should be counted correctly. There have been proposed various methods to realize the requirements. Some of them require anonymous communication paths as necessary elements to satisfy the anonymity requirement for a practical electronic voting system. Cruz et al. proposed an electronic voting system that does not need anonymous communication paths, using Bitcoin, a cryptographic currency, as a distributed database. However, Bitcoin is a system in which all data are disclosed, and anyone can check what exchanges a person of a certain ID (Bitcoin address) has done. It is possible to reveal which voter made what vote, and hence(anonymity is not satisfied. In this paper, we propose a method to solve the above problem by using Bitcoin mixing. We propose an electronic voting system using Zerocoin, a variant of Bitcoin, as a database, in which zero knowledge proof is used instead of blind signature for mixing.
As the most fundamental infrastructure in the current Internet, the Border Gateway Protocol (BGP) supports the inter-connectivity of different Autonomous Systems (ASs) and then the reachability can be achieved from any network in the Internet. However, due to the lack of security consideration during its original design, the BGP suffers from multiple security threats. Another challenge is that it cannot support the future sophisticated applications with deterministic routing. In this article, we propose a novel BGP management architecture, namely BGPChain, which is based on the blockchain in order to establish a secure, smart, and agile routing infrastructure for the future Internet.
João Paulo de Brito Gonçalves, Henrique Carvalho de Resende, Esteban Municio, Rodolfo da Silva Villaça ¡ 5 authors
Network slicing is the 5G research field that addresses the services requirements compliance over the same network. In order to robustly and securely manage the different slices in a network, we propose to use blockchain, a distributed structure that stores data without the need of an external entity to ensure data integrity and reliability. In this paper, we present a proposal on deploying a network slicing solution for Non-Public Networks (NPNs) in health environments using blockchain technology. Our solution aims to provide both performance isolation over wireless networks and privacy.
Cyber threat is a major issue that has been terrorizing the computing work. A typical cyber-physical system is crucial in ensuring a safe and secure architecture of a sustainable computing ecosystem. Cyber Threat Intelligence (CTI) is a new methodology that is used to address some of the existing cyber threats and ensure a more secure environment for communication. Data credibility and reliability plays a vital role in increasing the potential of a typical CTI and the data collected for this purpose is said to be highly reliable. In this paper, we have introduced a CTI system using blockchain to tackle the issues of sustainability, scalability, privacy and reliability. This novel approach is capable of measuring organizations contributions, reducing network load, creating a reliable dataset and collecting CTI data with multiple feeds. We have testing various parameters to determine the efficiency of the proposed methodology. Experimental results show that when compared to other methodologies, we can save upto 20% of storage space using the proposed methodology.