Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,269 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,269 results · page 40 of 53

Clear filters
Nov 1, 2020·2020 IEEE International Conference on Blockchain (Blockchain)
15 cites
An Analysis of Routing Attacks Against IOTA Cryptocurrency

Pericle Perazzo, Antonio Arena, Gianluca Dini

IOTA is a new type of distributed ledger designed for allowing fee-less and rate-scalable micropayments in Internet of Things applications. Security research on IOTA has focused mainly on attacks involving its cryptographic operations or its consensus algorithm. In this paper, we present a preliminary analysis of the IOTA security with respect to malicious Autonomous Systems (ASes), which can intercept IOTA connections by manipulating routing advertisements (BGP hijacking) or by naturally intercepting traffic. We make the simplifying assumption that the malicious AS can intercept routes between hosts without causing side effects, or without these side effects being noticed by the intercepted hosts. We identify three notable attacks that can lead to permanent money freeze, and to local or global interruptions of the consensus mechanisms. We then analyze the vulnerability of IOTA against malicious ASes on the real Internet topology, and we show that IOTA cryptocurrency is, at the time of writing, pretty susceptible of these attacks because quite centralized from the point of view of BGP routing. We then study the routing-level security of the next version of IOTA (post-coordicide), which has been proposed by the IOTA Foundations to make the cryptocurrency fully distributed.

Blockchain Technology Applications and Security
Distributed systems and fault tolerance
Network Security and Intrusion Detection
Original source
Nov 1, 2020·2020 IEEE International Conference on Blockchain (Blockchain)
16 cites
Android-based Cryptocurrency Wallets: Attacks and Countermeasures

Cong Li, Daojing He, Shihao Li, Sencun Zhu · 6 authors

The security of cryptocurrency wallets is directly related to the security of personal assets. However, due to the design defects of mobile operating system and cryptocurrency wallets, security incidents of cryptocurrency wallets occur frequently, causing irreversible losses to users' assets or privacy. In this paper, we study the security risks of Android-based cryptocurrency wallets. We establish the adversary model, analyze the attack surface originated from the Android OS, and demonstrate several attack vectors by conducting experiments on multiple popular cryptocurrency wallets in Google Play Store. Finally, we present several security defense strategies in response to the security risks.

Advanced Malware Detection Techniques
Digital and Cyber Forensics
Network Security and Intrusion Detection
Original source
Oct 30, 2020·2020 IEEE International Conference on Networking, Sensing and Control (ICNSC)
17 cites
Biologically Inspired Smart Contract: A Blockchain-Based DDoS Detection System

Xu Han, Rongbai Zhang, Xingzi Liu, Frank Jiang

With the increase of Internet usage, the identification and recovery from cyber-attacks become the major concerns for cyber industries. Therefore, the harm caused by network attacks has caused widespread concern. Distributed Denial of Service (DDoS) attack is a very common destructive cyber attack. This is a network attack that destroys the network and can cause multiple computers to be attacked at the same time, failing to perform services properly. Therefore, based on the understanding of blockchain structure and DDoS characteristics, a blockchain-based DDoS detection model framework is proposed to form a blockchain-based collaborative detection system. We use the blockchain consortium chain structure to treat all participants as part of the private chain in the system. Each participating organization has its own channel, and other organizations cannot access its information, thus fully protecting the privacy of each participant. Our experimental results show that smart contracts can detect DDoS data and generate anomalous chains on each node. The time required to generate an exception chain and information sharing is very short, which indicates that the system can protect the privacy of user data. While sharing data in time, good results can be obtained as a collaborative detection system.

Open access
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Original source
Oct 28, 2020·2020 8th International Conference on Wireless Networks and Mobile Communications (WINCOM)
20 cites
A Review: Collaborative Intrusion Detection for IoT integrating the Blockchain technologies

Hafsa Benaddi, Khalil Ibrahimi

Several anomaly detection systems prototypes are deployed to set up real-world solutions exclusively dedicated to the banking industry due to the high potentials of attacks. Exchanging highly security-sensitive data over a network between nodes requires high-security levels of IoT devices, representing a big challenge. Thus, many systems were developed to detect and predict any malicious activity. In our digital world, it is very challenging to master the fact that we, as a whole internet community, create an uncountable number of bytes of data every 24 hours. This truth leads researchers to explore and discover new technologies to handle massive data by ensuring individuals security and privacy. Inspired by this, our work supports researchers in this field by providing a selective overview of the most relevant findings investigating and proposing solutions on Intrusion Detection Systems (IDS) over the Internet of Thing (IoT). Furthermore, the Blockchain integration as the principal registry for safe data storage is well explained and detailed while covering security qualities that analyze and classify different confronted open challenges in this path.

Blockchain Technology Applications and Security
Network Security and Intrusion Detection
IoT and Edge/Fog Computing
Original source
Oct 28, 2020·2020 11th IEEE Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON)
26 cites
Cyber Fraud: Detection and Analysis of the Crypto-Ransomware

İlker Kara, Murat Aydos

Currently as the widespread use of virtual monetary units (like Bitcoin, Ethereum, Ripple, Litecoin) has begun, people with bad intentions have been attracted to this area and have produced and marketed ransomware in order to obtain virtual currency easily. This ransomware infiltrates the victim's system with smartly-designed methods and encrypts the files found in the system. After the encryption process, the attacker leaves a message demanding a ransom in virtual currency to open access to the encrypted files and warns that otherwise the files will not be accessible. This type of ransomware is becoming more popular over time, so currently it is the largest information technology security threat. In the literature, there are many studies about detection and analysis of this cyber-bullying. In this study, we focused on crypto-ransomware and investigated a forensic analysis of a current attack example in detail. In this example, the attack method and behavior of the crypto-ransomware were analyzed and it was identified that information belonging to the attacker was accessible. With this dimension, we think our study will significantly contribute to the struggle against this threat.

Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Information and Cyber Security
Original source
Oct 23, 2020·arXiv (Cornell University)
4 cites
Bet and Attack: Incentive Compatible Collaborative Attacks Using Smart Contracts

Zahra Motaqy, Ghada Almashaqbeh, Behnam Bahrak, Naser Yazdani

Smart contract-enabled blockchains allow building decentralized applications in which mutually-distrusted parties can work together. Recently, oracle services emerged to provide these applications with real-world data feeds. Unfortunately, these capabilities have been used for malicious purposes under what is called criminal smart contracts. A few works explored this dark side and showed a variety of such attacks. However, none of them considered collaborative attacks against targets that reside outside the blockchain ecosystem. In this paper, we bridge this gap and introduce a smart contract-based framework that allows a sponsor to orchestrate a collaborative attack among (pseudo)anonymous attackers and reward them for that. While all previous works required a technique to quantify an attacker's individual contribution, which could be infeasible with respect to real-world targets, our framework avoids that. This is done by developing a novel scheme for trustless collaboration through betting. That is, attackers bet on an event (i.e., the attack takes place) and then work on making that event happen (i.e., perform the attack). By taking DDoS as a usecase, we formulate attackers' interaction as a game, and formally prove that these attackers will collaborate in proportion to the amount of their bets in the game's unique equilibrium. We also model our framework and its reward function as an incentive mechanism and prove that it is a strategy proof and budget-balanced one. Finally, we conduct numerical simulations to demonstrate the equilibrium behavior of our framework.

Open access
3 source records
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Spam and Phishing Detection
Original source
Oct 18, 2020·IEEE Transactions on Systems Man and Cybernetics Systems
73 cites
Blockchain-Based Decentralized Replay Attack Detection for Large-Scale Power Systems

Paritosh Ramanan, Dan Li, Nagi Gebraeel

Large-scale power systems are composed of regional utilities with assets that stream sensor readings in real time. In order to detect cyberattacks, the globally acquired, real-time sensor data needs to be analyzed in a centralized fashion. However, owing to operational constraints, such a centralized sharing mechanism turns out to be a major obstacle. In this article, we propose a blockchain-based decentralized framework for detecting coordinated replay attacks with full privacy of sensor data. We develop a Bayesian inference mechanism employing locally reported attack probabilities that is tailor made for a blockchain framework. We compare our framework to a traditional decentralized algorithm based on the broadcast gossip framework both theoretically as well as empirically. With the help of experiments on a private Ethereum blockchain, we show that our approach achieves good detection quality and significantly outperforms gossip-driven approaches in terms of accuracy, timeliness, and scalability.

Open access
3 source records
Smart Grid Security and Resilience
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Original source
Oct 14, 2020·2020 6th Information Technology International Seminar (ITIS)
15 cites
Blacklisted IP Distribution System to handle DDoS attacks on IPS Snort based on Blockchain

Bram Andika Ahmad Al`Aziz, Parman Sukarno, Aulia Arif Wardana

The mechanism for distributing information on the source of the attack by combining blockchain technology with the Intrusion Prevention System (IPS) can be done so that DDoS attack mitigation becomes more flexible, saves resources and costs. Also, by informing the blacklisted Internet Protocol(IP), each IPS can share attack source information so that attack traffic blocking can be carried out on IPS that are closer to the source of the attack. Therefore, the attack traffic passing through the network can be drastically reduced because the attack traffic has been blocked on the IPS that is closer to the attack source. The blocking of existing DDoS attack traffic is generally carried out on each IPS without a mechanism to share information on the source of the attack so that each IPS cannot cooperate. Also, even though the DDoS attack traffic did not reach the server because it had been blocked by IPS, the attack traffic still flooded the network so that network performance was reduced. Through smart contracts on the Ethereum blockchain, it is possible to inform the source of the attack or blacklisted IP addresses without requiring additional infrastructure. The blacklisted IP address is used by IPS to detect and handle DDoS attacks. Through the blacklisted IP distribution scheme, testing and analysis are carried out to see information on the source of the attack on each IPS and the attack traffic that passes on the network. The result is that each IPS can have the same blacklisted IP so that each IPS can have the same attack source information. The results also showed that the attack traffic through the network infrastructure can be drastically reduced. Initially, the total number of attack packets had an average of 115,578 reduced to 27,165.

Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Original source
Oct 13, 2020·2020 IEEE 28th International Conference on Network Protocols (ICNP)
4 cites
Preventing Route Leaks using a Decentralized Approach: An Experimental Evaluation

Miquel Ferriol-Galmés, Roger Coll Aumatell, Albert Cabellos‐Aparicio, Shoushou Ren · 6 authors

In the inter-domain routing infrastructure, a route leak is defined as a violation of the routing policy agreed between two Autonomous Systems (AS). Route leaks have resulted in large-scale outages on the Internet, taking down several services. Although route leaks seem a simple problem, the solution is complex because: (i) ASes consider -partially- routing policy private, (ii) lack of a formal and standard language to express routing policy and (iii) BGP lacks adequate cryptographic-based security. In this paper, we present an experimental analysis of a distributed ledger-based architecture that provides a solution to route leaks. Specifically, the routing policy is unambiguously expressed using a formal language, that is then stored in a blockchain. This decentralized architecture allows private policies and interfaces seamlessly with the current BGP infrastructure, requiring no changes to routers. We build a prototype to evaluate our proposed architecture using Hyperledger, we analyze its performance using a real-world BGP dataset. Our results show that our architecture scales linearly with relevant metrics. Additionally, we validate the architecture preventing an artificially introduced route leak in a realistic 10 AS topology.

Open access
Internet Traffic Analysis and Secure E-voting
Network Security and Intrusion Detection
Network Packet Processing and Optimization
Original source
Oct 11, 2020·Transactions on Emerging Telecommunications Technologies
40 cites
Enabling security for the Industrial Internet of Things using deep learning, blockchain, and coalitions

Mehul Sharma, Shrid Pant, Deepak Kumar Sharma, Koyel Datta Gupta · 6 authors

Abstract In a wireless Industrial Internet of Things (IIoT) network, enforcing security is a challenge due to the large number of devices forming the network and their limited computation capabilities. Furthermore, different security attacks require specifically tailored security protocols to prevent their occurrence. As an alternative to these conventional centralized security protocols, the application of Blockchain (BC) and Deep learning (DL) for securing IIoT networks hold great potential. BC facilitates security by being an immutable record of the changes happening in a network. Coalition Formation theory aids decentralization and promotes energy efficiency. And to enforce a state‐of‐the‐art attack detection technique, Deep learning provides an adaptive and reliable platform. Thus, in this paper, a security framework that facilitates generalized security for the IIoT network using BC and Coalition Formation theory is proposed. Additionally, we promote a sophisticated deep learning‐based classification algorithm to efficiently classify malicious and benign devices in IIoT scenarios. In the proposed model, connection links can only be established if the details of the connection are mined on the BC by the “sender” device. Therefore, we propose a Proof of Reliance algorithm that dynamically increases the computational difficulty to prevent malicious devices from attacking the network. Through simulations, it is experimentally proven that malicious devices can never attack the network when the proposed framework is employed for IIoT security.

Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Smart Grid Security and Resilience
Original source
Oct 8, 2020·Open Repository and Bibliography (University of Luxembourg)
1 cites
Machine Learning Techniques for Suspicious Transaction Detection and Analysis

Ramiro Daniel Camino

Financial services must monitor their transactions to prevent being used for money laundering and combat the financing of terrorism. Initially, organizations in charge of fraud regulation were only concerned about financial institutions such as banks. However, nowadays, the Fintech industry, online businesses, or platforms involving virtual assets can also be affected by similar criminal schemes. Regardless of the differences between the entities mentioned above, malicious activities affecting them share many common patterns. This dissertation's first goal is to compile and compare existing studies involving machine learning to detect and analyze suspicious transactions. The second goal is to synthesize methodologies from the last goal for tackling different use cases in an organized manner. Finally, the third goal is to assess the applicability of deep generative models for enhancing existing solutions. In the first part of the thesis, we propose an unsupervised methodology for detecting suspicious transactions applied to two case studies. One is related to transactions from a money remittance network, and the other is related to a novel payment network based on distributed ledger technologies. Anomaly detection algorithms are applied to rank user accounts based on recency, frequency, and monetary features. The results are manually validated by domain experts, confirming known scenarios and finding unexpected new cases. In the second part, we carry out an analogous analysis employing supervised methods, along with a case study where we classify Ethereum smart contracts into honeypots and non-honeypots. We take features from the source code, the transaction data, and the funds' flow characterization. The proposed classification models proved to generalize well to unseen honeypot instances and techniques and allowed us to characterize previously unknown techniques. In the third part, we analyze the challenges that tabular data brings into the domain of deep generative models, a particular type of data used to represent financial transactions in the previous two parts. We propose a new model architecture by adapting state-of-the-art methods to output multiple variables from mixed types distributions. Additionally, we extend the evaluation metrics used in the literature to the multi-output setting, and we show empirically that our approach outperforms the existing methods. Finally, in the last part, we extend the work from the third part by applying the presented models to enhance classification tasks from the second part, commonly containing a severe class imbalance. We introduce the multi-input architecture to expand models alongside our previously proposed multi-output architecture. We compare three techniques to sample from deep generative models defining a transparent and fair large-scale experimental protocol and interesting visual analysis tools. We showed that general machine learning detection and visualization techniques could help address the fraud detection domain's many challenges. In particular, deep generative models can add value to the classification task given the imbalanced nature of the fraudulent class, in exchange for implementation and time complexity. Future and promising applications for deep generative models include missing data imputation and sharing synthetic data or data generators preserving privacy constraints.

Open access
Network Security and Intrusion Detection
Anomaly Detection Techniques and Applications
Software System Performance and Reliability
Original source
Sep 13, 2020·Transactions on Emerging Telecommunications Technologies
163 cites
A Distributed framework for detecting DDoS attacks in smart contract‐based Blockchain‐IoT Systems by leveraging Fog computing

Prabhat Kumar, Randhir Kumar, Govind P. Gupta, Rakesh Tripathi

Abstract With the advancement of blockchain technology, and the proliferation of Internet of things (IoT)‐driven devices, the blockchain‐IoT applications is changing the perception and working infrastructure of smart networks. Blockchain supports decentralized architecture and provides secure management, authentication, and access to IoT systems by deploying smart contracts provided by Ethereum. The growing demand and expansion of blockchain‐IoT systems is generating large volume of sensitive data. Moreover, distributed denial‐of‐service (DDoS) attacks are the most challenging threats to smart contracts in blockchain‐IoT systems. The 2016 decentralized autonomous organization and 2017 parity wallet attacks exposed the critical fault‐lines among Ethereum smart contracts. Currently, there is no security mechanism available for smart contracts after its deployment in blockchain‐IoT systems. In order to address these challenges, first we use two artificial intelligence techniques, random forest (RF) and XGBoost that gives full autonomy in decision making capabilities in the proposed security framework. Second, for data load balancing and distributed file storage of IoT data, interplanetary file system is suggested. Finally, we are the first to propose a distributed framework based on fog computing to detect DDoS attacks in smart contracts. The performance of the detection system is evaluated using actual IoT dataset, namely, BoT‐IoT. The proposed system is evaluated in terms of accuracy (AC), detection rate (DR), and false alarm rate (FAR). The results confirms the superiority of the proposed framework over some of the recent state‐of‐art techniques in detecting rare attacks. The proposed framework has achieved DR up to 99.99% using RF by using 10 features of BoT‐IoT dataset.

2 source records
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
Original source
Sep 5, 2020·Peer-to-Peer Networking and Applications
95 cites
Penetration testing framework for smart contract Blockchain

Akashdeep Bhardwaj, Syed Bilal Hussain Shah, Achyut Shankar, Mamoun Alazab · 6 authors

No abstract is available for this record.

Advanced Malware Detection Techniques
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Original source
Sep 1, 2020·2020 2nd Conference on Blockchain Research & Applications for Innovative Networks and Services (BRAINS)
19 cites
DefenseChain: Consortium Blockchain for Cyber Threat Intelligence Sharing and Defense

Soumya Purohit, Prasad Calyam, Songjie Wang, RajaniKanth Yempalla · 5 authors

Cloud-hosted applications are prone to targeted attacks such as DDoS, advanced persistent threats, cryptojacking which threaten service availability. Recently, methods for threat information sharing and defense require co-operation and trust between multiple domains/entities. There is a need for mechanisms that establish distributed trust to allow for such a collective defense. In this paper, we present a novel threat intelligence sharing and defense system, namely “DefenseChain”, to allow organizations to have incentive-based and trustworthy co-operation to mitigate the impact of cyber attacks. Our solution approach features a consortium Blockchain platform to obtain threat data and select suitable peers to help with attack detection and mitigation. We propose an economic model for creation and sustenance of the consortium with peers through a reputation estimation scheme that uses ‘Quality of Detection’ and ‘Quality of Mitigation’ metrics. Our evaluation experiments with DefenseChain implementation are performed on an Open Cloud testbed with Hyperledger Composer and in a simulation environment. Our results show that the DefenseChain system overall performs better than state-of-the-art decision making schemes in choosing the most appropriate detector and mitigator peers. In addition, we show that our DefenseChain achieves better performance trade-offs in terms of metrics such as detection time, mitigation time and attack reoccurence rate. Lastly, our validation results demonstrate that our DefenseChain can effectively identify rational/irrational service providers.

Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Information and Cyber Security
Original source
Sep 1, 2020·China Communications
45 cites
Anti-D chain: A lightweight DDoS attack detection scheme based on heterogeneous ensemble learning in blockchain

Bin Jia, Yongquan Liang

With rapid development of blockchain technology, blockchain and its security theory research and practical application have become crucial. At present, a new DDoS attack has arisen, and it is the DDoS attack in blockchain network. The attack is harmful for blockchain technology and many application scenarios. However, the traditional and existing DDoS attack detection and defense means mainly come from the centralized tactics and solution. Aiming at the above problem, the paper proposes the virtual reality parallel an-ti-DDoS chain design philosophy and distributed anti-D Chain detection framework based on hybrid ensemble learning. Here, AdaBoost and Random Forest are used as our ensemble learning strategy, and some different lightweight classifiers are integrated into the same ensemble learning algorithm, such as CART and ID3. Our detection framework in block-chain scene has much stronger generalization performance, universality and complementarity to identify accurately the onslaught features for DDoS attack in P2P network. Extensive experimental results confirm that our distributed heterogeneous anti-D chain detection method has better performance in six important indicators (such as Precision, Recall, F-Score, True Positive Rate, False Positive Rate, and ROC curve).

Network Security and Intrusion Detection
Anomaly Detection Techniques and Applications
Advanced Malware Detection Techniques
Original source
Aug 24, 2020·Journal of Network and Systems Management
32 cites
Blockchain Signaling System (BloSS): Cooperative Signaling of Distributed Denial-of-Service Attacks

Bruno Rodrigues, Eder J. Scheid, Christian Killer, Muriel Figueredo Franco · 5 authors

Abstract Distributed Denial-of-Service (DDoS) attacks are one of the major causes of concerns for communication service providers. When an attack is highly sophisticated and no countermeasures are available directly, sharing hardware and defense capabilities become a compelling alternative. Future network and service management can base its operations on equally distributed systems to neutralize highly distributed DDoS attacks. A cooperative defense allows for the combination of detection and mitigation capabilities, the reduction of overhead at a single point, and the blockage of malicious traffic near its source. Main challenges impairing the widespread deployment of existing cooperative defense are: (a) high complexity of operation and coordination, (b) need for trusted and secure communications, (c) lack of incentives for service providers to cooperate, and (d) determination on how operations of these systems are affected by different legislation, regions, and countries. The cooperative Blockchain Signaling System ( BloSS ) defines an effective and alternative solution for security management, especially cooperative defenses, by exploiting Blockchains (BC) and Software-Defined Networks (SDN) for sharing attack information, an exchange of incentives, and tracking of reputation in a fully distributed and automated fashion. Therefore, BloSS was prototyped and evaluated through a global experiment, without the burden to maintain, design, and develop special registries and gossip protocols.

Open access
Network Security and Intrusion Detection
Blockchain Technology Applications and Security
Advanced Malware Detection Techniques
Original source
Aug 11, 2020·Sensors
12 cites
Enhancing Border Gateway Protocol Security Using Public Blockchain

Lukas Mastilak, Marek Galinski, Pavol Helebrandt, Ivan Kotuliak · 5 authors

Communication on the Internet consisting of a massive number of Autonomous Systems (AS) depends on routing based on Border Gateway Protocol (BGP). Routers generally trust the veracity of information in BGP updates from their neighbors, as with many other routing protocols. However, this trust leaves the whole system vulnerable to multiple attacks, such as BGP hijacking. Several solutions have been proposed to increase the security of BGP routing protocol, most based on centralized Public Key Infrastructure, but their adoption has been relatively slow. Additionally, these solutions are open to attack on this centralized system. Decentralized alternatives utilizing blockchain to validate BGP updates have recently been proposed. The distributed nature of blockchain and its trustless environment increase the overall system security and conform to the distributed character of the BGP. All of the techniques based on blockchain concentrate on inspecting incoming BGP updates only. In this paper, we improve on these by modifying an existing architecture for the management of network devices. The original architecture adopted a private blockchain implementation of HyperLedger. On the other hand, we use the public blockchain Ethereum, more specifically the Ropsten testing environment. Our solution provides a module design for the management of AS border routers. It enables verification of the prefixes even before any router sends BGP updates announcing them. Thus, we eliminate fraudulent BGP origin announcements from the AS deploying our solution. Furthermore, blockchain provides storage options for configurations of edge routers and keeps the irrefutable history of all changes. We can analyze router settings history to detect whether the router advertised incorrect information, when and for how long.

Open access
Blockchain Technology Applications and Security
Internet Traffic Analysis and Secure E-voting
Network Security and Intrusion Detection
Original source
Aug 9, 2020·Sustainability
52 cites
Blockchain-Based Cyber Threat Intelligence System Architecture for Sustainable Computing

Jeonghun Cha, Sushil Kumar Singh, Yi Pan, Jong Hyuk Park

Nowadays, the designing of cyber-physical systems has a significant role and plays a substantial part in developing a sustainable computing ecosystem for secure and scalable network architecture. The introduction of Cyber Threat Intelligence (CTI) has emerged as a new security system to mitigate existing cyber terrorism for advanced applications. CTI demands a lot of requirements at every step. In particular, data collection is a critical source of information for analysis and sharing; it is highly dependent on the reliability of the data. Although many feeds provide information on threats recently, it is essential to collect reliable data, as the data may be of unknown origin and provide information on unverified threats. Additionally, effective resource management needs to be put in place due to the large volume and diversity of the data. In this paper, we propose a blockchain-based cyber threat intelligence system architecture for sustainable computing in order to address issues such as reliability, privacy, scalability, and sustainability. The proposed system model can cooperate with multiple feeds that collect CTI data, create a reliable dataset, reduce network load, and measure organizations’ contributions to motivate participation. To assess the proposed model’s effectiveness, we perform the experimental analysis, taking into account various measures, including reliability, privacy, scalability, and sustainability. Experimental results of evaluation using the IP of 10 open source intelligence (OSINT) CTI feeds show that the proposed model saves about 15% of storage space compared to total network resources in a limited test environment.

Open access
Blockchain Technology Applications and Security
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source
Aug 5, 2020·Sensors
36 cites
Edge Computing and Blockchain for Quick Fake News Detection in IoV

Yonggang Xiao, Yanbing Liu, Tun Li

The dissemination of false messages in Internet of Vehicles (IoV) has a negative impact on road safety and traffic efficiency. Therefore, it is critical to quickly detect fake news considering news timeliness in IoV. We propose a network computing framework Quick Fake News Detection (QcFND) in this paper, which exploits the technologies from Software-Defined Networking (SDN), edge computing, blockchain, and Bayesian networks. QcFND consists of two tiers: edge and vehicles. The edge is composed of Software-Defined Road Side Units (SDRSUs), which is extended from traditional Road Side Units (RSUs) and hosts virtual machines such as SDN controllers and blockchain servers. The SDN controllers help to implement the load balancing on IoV. The blockchain servers accommodate the reports submitted by vehicles and calculate the probability of the presence of a traffic event, providing time-sensitive services to the passing vehicles. Specifically, we exploit Bayesian Network to infer whether to trust the received traffic reports. We test the performance of QcFND with three platforms, i.e., Veins, Hyperledger Fabric, and Netica. Extensive simulations and experiments show that QcFND achieves good performance compared with other solutions.

Open access
Vehicular Ad Hoc Networks (VANETs)
Network Security and Intrusion Detection
Caching and Content Delivery
Original source
Aug 1, 2020·Security and Communication Networks
41 cites
Distributed Security Framework for Reliable Threat Intelligence Sharing

Davy Preuveneers, Wouter Joosen, Jorge Bernal Bernabé, Antonio Skármeta

Computer security incident response teams typically rely on threat intelligence platforms for information about sightings of cyber threat events and indicators of compromise. Other security building blocks, such as Network Intrusion Detection Systems, can leverage the information to prevent malicious adversaries from spreading malware across critical infrastructures. The effectiveness of threat intelligence platforms heavily depends on the willingness to share among organizations and the responsible use of sensitive information that may potentially harm the reputation of the reporting organization. The challenge that we address is the lack of trust in the source providing the threat intelligence and the information itself. We enhance our security framework TATIS—offering fine-grained protection for threat intelligence platform APIs—with distributed ledger capabilities to enable reliable and trustworthy threat intelligence sharing with the ability to audit the provenance of threat intelligence. We have implemented and evaluated the feasibility of our distributed framework on top of the Malware Information Sharing Platform (MISP) solution, and we evaluate the performance impact using real-world open-source threat intelligence feeds.

Open access
Advanced Malware Detection Techniques
Network Security and Intrusion Detection
Information and Cyber Security
Original source
Jul 30, 2020·arXiv (Cornell University)
0 cites
Implications of Dissemination Strategies on the Security of Distributed\n Ledgers

Luca Serena, Gabriele D’Angelo, Stefano Ferretti

This paper describes a simulation study on security attacks over Distributed\nLedger Technologies (DLTs). We specifically focus on attacks at the underlying\npeer-to-peer layer of these systems, that is in charge of disseminating\nmessages containing data and transaction to be spread among all participants.\nIn particular, we consider the Sybil attack, according to which a malicious\nnode creates many Sybils that drop messages coming from a specific attacked\nnode, or even all messages from honest nodes. Our study shows that the\nselection of the specific dissemination protocol, as well as the amount of\nconnections each peer has, have an influence on the resistance to this attack.\n

Open access
Peer-to-Peer Network Technologies
Network Security and Intrusion Detection
Caching and Content Delivery
Original source