Νικόλαος Αλεξόπουλος, Emmanouil Vasilomanolakis, Stéphane Le Roux, Steven Rowe · 5 authors
Sophisticated mass attacks, especially when exploiting zero-day vulnerabilities, have the potential to cause destructive damage to organizations and critical infrastructure. To timely detect and contain such attacks, collaboration among the defenders is critical. By correlating real-time detection information (threat indicators) from multiple sources, defenders can detect attacks and take the appropriate measures in time. However, although the technical tools to facilitate collaboration exist, real-world adoption of such collaborative security mechanisms is still underwhelming. This is largely due to a lack of trust and participation incentives for companies and organizations. This paper proposes TRIDEnT, a novel collaborative platform that aims to enable parties to exchange network threat indicators, thus increasing their overall detection capabilities. TRIDEnT allows parties that may be in a competitive relationship, to selectively advertise, sell and acquire threat indicators in the form of (near) real-time peer-to-peer streams. To demonstrate the feasibility of our approach, we instantiate our design in a decentralized manner using Ethereum smart contracts and provide a fully functional prototype.
Background/Objectives: Tremendous growth of information and communication technologies (ICTs) have positively affected the field of E-Learning (EL). However, recently the education mode is shifted from the traditional classroom towards EL due to widespread COVID-19. The selection of suitable EL tool and security of EL data and environment are still the key challenges that need to be addressed. The objective of this paper is to guide the EL Practitioners in the selection of suitable EL tool and to provide a detailed framework for maintaining privacy and security of EL data and environment. Purpose: This study aims to help EL practitioners in the selection of suitable EL tool and to provide a secure framework for the security of EL data and environment. Method: Realtime statistics are gathered and analyzed to visualize the impact of COVID-19 on education around the world. The increasing demand for EL during COVID-19 is analyzed, and a detailed taxonomy is provided to make the EL practitioners aware of existing distance learning solutions. A comparison of commonly used EL tools is provided that will help in the selection of EL tools according to institutional requirements. A Blockchain-based EL framework is proposed that will help EL designer in managing the security of EL data and environment. Conclusion: The proposed framework is expected to provide a promising solution for developing a fair and open learning online education environment and will overcome the deficiencies caused by school closures during COVID-19. Keywords: COVID-19; Blockchain; Security; Privacy; E-Learning; Digital Curriculum
With the rise of cloud computing, data centers, and big data, the current rigid network architecture has been found to be inadequate. The modern technological demands require a flexible and easily reconfigurable network architecture. Software Defined Networking is a revolutionary concept that separates the control plane of network devices from their data plane and centralizes the control plane of all devices, facilitating the controlling of the entire network through a single portal. This helps us create flexible network architectures that can be reconfigured quickly to fit different needs. However, centralizing control leads to a Single Point of Failure and makes the network vulnerable to Denial of Service attacks, which is one of the major reasons why industries are reluctant to adopt this technology. Blockchain provides us a with a distributed ledger and a decentralized state, allowing us to create decentralized applications that run over multiple computers. This research aims to distribute the control plane of Software Defined Networks across multiple devices using blockchain. This addresses the existing security vulnerabilities of the Software Defined Network architecture such as Single Point of Failure while continuing to keep the control plane logically centralized, thereby allowing the network to be configured through a single portal. The resulting architecture has a physically distributed control plane whose logic is centralized.
Lo‐Yao Yeh, Peggy Joy Lu, Szu-Hao Huang, Jiun‐Long Huang
IoT devices provide a significant medium for distributed denial-of-service (DDoS) attacks. In 2016, a large-scale DDoS attack, named Dyn, caused massive damage to several well-known companies. One effective countermeasure is observing previous network traffic information or abnormal behavior determined by the host machines and determining the latest DDoS-attack IP addresses. Because of the lack of a fair exchange mechanism, most security operation centers (SOCs) are unwilling to share their real-time DDoS data. In this article, we propose a decentralized DDoS data exchange platform, namely SOChain, using blockchain technology to overcome the trust and fairness issues. The platform incentivizes SOCs through the DDoS_coin token. The more DDoS information an SOC contributes, the more coins it earns. To confirm the validity of uploaded information, we enlist a content verifier to examine uploaded abnormal IP addresses. Moreover, the verifier is incentivized by the DDoS_coin. To decrease the management effort, the entire flow is automatically executed in smart contract deployed onto the blockchain system. To address the issue of privacy in smart contracts, we devise a novel dual-level Bloom filter to enable efficient searches with privacy protection. Herein, a verifiable method is designed without revealing the information to public.
Increasingly growing Cryptocurrency markets have become a hive for scammers to run pump and dump schemes which is considered as an anomalous activity in exchange markets. Anomaly detection in time series is challenging since existing methods are not sufficient to detect the anomalies in all contexts. In this paper, we propose a novel hybrid pump and dump detection method based on distance and density metrics. First, we propose a novel automatic thresh-old setting method for distance-based anomaly detection. Second, we propose a novel metric called density score for density-based anomaly detection. Finally, we exploit the combination of density and distance metrics successfully as a hybrid approach. Our experiments show that, the proposed hybrid approach is reliable to detect the majority of alleged P & D activities in top ranked exchange pairs by outperforming both density-based and distance-based methods.
Mining pools have become dominant in today's bitcoin mining network, where miners can pool their powers together for reduced variance of block mining and steadier stream of potential income. Along with the continuous evolvement of mining pools are the increasingly intense competitions among them. Recent empirical studies have shown that the distributed denial-of-service (DDoS) attack is one of the most common ways for competing mining pools to sabotage the rivals and earn illegitimate rewards. Existing efforts have been made on using static game models to analyze the interactions between mining pools, and derive the Nash Equilibrium and optimal attacking strategies in a one-time static context. To better understand the impact of such DDoS attacks, in this paper, we take a starkly different approach, and for the first time address the dynamics in mining pool attacks. Specifically, we start by formulating the interactive competition among mining pools as a general-sum stochastic game. Then we propose an efficient Nash learning algorithm to obtain the near optimal attacking strategy that maximizes the expected long-term utility. Our theoretical analysis and extensive experimental results both show that the proposed strategy outperforms the baseline myopic learning algorithm, which only aims at maximizing the revenue in the current time stage. These findings, together with our proposed stochastic game model and learning algorithm, are expected to provide more practical guidelines for mining pools to survive and thrive in the highly-competitive bitcoin ecosystem.
Bo Zhao, Yifan Liu, Xiang Li, Jiayue Li · 5 authors
The data layer devices in the Software Defined Network (SDN) play an important role in packet forwarding. However, whether the forwarding task can be efficiently completed by the node has not attracted enough attention. A method called TrustBlock is proposed in this paper, which introduces trust as a security attribute in SDN routing planning. Besides, in order to enhance the integrity and controllability of trust evaluation, the double-layer blockchain architecture is established. In the first layer, the behavior data of the node is recorded, and then the trust calculation is performed in the second layer. In the evaluation model, nodes' trust is calculated from three aspects: direct trust, indirect trust and historical trust. Firstly, from the perspective of security, blockchain is used to achieve identity authentication of nodes, after that, from the perspective of reliability, the forwarding status is used to calculate the trust value. Secondly, consensus algorithm is used to filter malicious recommendation trust value and prevent colluding attacks. Finally, the adaptive historical trust weight is designed to prevent the periodic attack. In this paper, the entropy method is used to determine the weight of each evaluation attribute, which can avoid the problem that the subjective judgment method is not adaptable to the weight setting. Simulation results show that the detection rate of the TrustBlock is up to 98.89%, which means this model can effectively identify the abnormal nodes in SDN. Moreover, it is attractive in terms of integrity and controllability.
Vikram Puri, Ishaani Priyadarshini, Raghvendra Kumar, Long Cu Kim
Industry 4.0 articulates that modern intelligent machines are better than humans that are enough capable to capture and analyze data in real-time, as well as in communicating information that may be helpful to take business-related decisions faster. The Industrial Internet of Things (IIoT) relies on intelligent assets that communicate and store data, data communication infrastructures, analytics, and people for functioning. With so many constituents of the IIoT network, there is also an increased potential for security risks. Privacy and trust issues need to be addressed. Recently Blockchain Technology has shown tremendous growth due to its reliable nature. In this paper we introduce a blockchain technology-based architecture for IIoT with the aim to address a lot of significant security issues
The block chain is attaining popularity day to day as it is acting as distributed ledger for Cryptocurrency such as Bitcoin and ripple. This research paper has focused on the Blockchain and its working pattern with technical implementation of block creation. This technical paper is considering the prevention of DNS Cache poisoning attack in Blockchain which is known as larger class of name-based attacks. DNS Packet interceptions may be made using various attacks like Cache poisoning attack, man-in-the-middle attacks etc. As there are numerous security mechanisms to secure the Blockchain but in order to make Blockchain immune from cache poisoning attack, there is need to update the block creation module. Therefore, this research work is proposed to make reduction in probability of data corruption that can be created from different attacks. It resolves the issue of cache poisoning attacks using user defined port instead of predefined port. However, the initialization of transmission is performed here using predefined port number. In second step, the encrypted port number is decrypted to initiate communication using user defined port number. The use of port with IP address would restrict attacks during data transmission. The paper has presented the comparative analysis of existing DNS attacking prevention mechanism to proposed work.
Privacy and Trust are critical issues in automation systems/ transportation systems. Today’s Vehicle is need of everyone for moving one place to another. Together this, data security plays an important role in automation systems as critical user’s (vehicle’s user) data is moved to another user though internet with the help of wireless devices and routes which includes optical fiber, radio channels, etc. In fact, each and every device is connected to the internet and is linked to each other, thus forming the Internet of Things (IoT). As the network is moving towards wireless applications, many threats to vehicles (autonomous vehicles) are becoming a critical problem for vehicles users and service providers. A majority of these attacks can be spotted and detected with the hep of a number of intrusion detection techniques which were elucidated in the earlier decade. These techniques are highly efficient in the identification of any form of individual breaches into the system by catching hold of invalid data access. A few of the systems which need safety are an integral part of Wireless Networks which consist of WLANs (Wireless Local Area Networks), WPANs (Wireless Personal Area Networks), etc. WPAN family further constitutes of three networks which are WSNs (Wireless Sensor Networks), mobile phones and RFID (Radio Frequency Identification like On Board Units (OBUs)). Since digitization is taking place in each and every sector, i.e., defence, healthcare, education, automation industries etc., and so the threat to data also exist. In this article, we protect IoT based environment based smart/ Intelligent Transportation Systems (ITS) using a novel concept “Blockchain Technology”. With proposing novel solution called ‘’PChain using Blockchain Technology (BT), we received many benefit in ITS’s applications. We discuss several open issues and challenges for the respective technology in near future (or next decade).
Wilfridus Bambang Triadi Handaya, Mohd Najwadi Yusoff, Aman Jantan
Abstract Cybercrime is the highest threat to every private company and government agency in the world. Using synergistic threats to attack provides many success alternatives that lead to the same goal, which is to take over the network and carry out illegal mining activities using CPU resources from the victim’s computer. One of the main motives for the success of this criminal business is its relatively low cost and high return of investment. Using the infection chain method in carrying out cryptocurrency mining malware attacks with fileless techniques involves loading malicious code into system memory. Monero (XMR) is by far the highest popular cryptocurrency among threat actor installing mining malware because it comes with full anonymity and resistance to an application-specific circuit mining (ASIC). This work proposes a better method for classifying conventional malware and cryptocurrency mining malware. On the other hand, grouping specific of suitable features extracted from the sources of EMBER dataset shown as malware and need to categorize as a cryptocurrency mining malware. The proposed approach is defining a better algorithm for enhancing accuracy and efficiency for cryptocurrency mining malware detection.
Applying watermarking protocols can effectively support the copyright protection to identify illegal distributors over the World Wide Web. Several schemes have been developed for copyright protection of the web based digital contents distributed over the internet. However, these protocols are often needs more complex security actions to be performed by the web based content providers for preserving the integrity of their content. In this paper, we propose a new secure web-based watermarking scheme based on the combination of the security of the public key cryptosystem (PKI) and the watermarking based on threshold cryptography. The proposed watermarking protocol solve the collude problem for the trusted certificate authority (CA) and applies the idea of the zero knowledge proof for verification purposes. Implementation and analysis of the proposed scheme has been conducted.
Shakkeera L, Hem Pransanth K C, Sabareesh, Sumaiya Begum · 5 authors
In today’s era, the cloud database security is one of the main concerns for any of the real time data accessing web/mobile applications. The cloud database protection involves accessibility and vulnerability of data, data protection, storage space, integrity and confidentiality on sensitive data. Building an electronic voting system that tries to completely fulfill the needs of the people has always been a challenge to achieve. The existing E-Voting System (E-VS) is not that much compatible with that of the current trends and does not assure to provide more security A lot of distributed ledger technologies which has been an exciting approach during existing election voting process. If we take a look on the ways of implying E-VS in a distribute ledger then Blockchain would be the right choice. As we all know that nowadays, Blockchain is one of the emerging technologies in the field of Information Technology. It normally stores information in batches called blocks which are linked together in a chronological way or method to form chain of blocks using cryptography techniques. During online voting process, many fraudulent activities happens which corrupt the entire election process. One of the major problems faced are fake voting which is obviously done by unauthorized people, inconvenient to reach to the respective places, average security level which may lead to the chances of an electoral fraud or any other malpractices.. Our proposed E-Voting System is mainly to protect the cloud database for real time data and to reduce the time consumption in voting and vote counting processes. Instead of standing in the queue for casting the vote, people can cast their votes from anywhere they want through online. The E-VS gives complete privacy and security for the online voting and makes it an ease for every individual to access it and cast their votes from anywhere possible with full pronounced security. In our proposed E-VS, Blockchain security concept called Consensus algorithm is implemented which makes it impossible for any unwanted activities to occur during election process. The E-VS system also achieves a higher level of security. Hence, the proposed system achieves data integrity, data confidentiality, eliminates storage overhead, and reduces time consumption for overall electronic voting system.
Christopher Klinkmüller, Ingo Weber, Alexander Ponomarev, An Binh Tran · 5 authors
Second generation blockchain platforms, like Ethereum, can store arbitrary data and execute user-defined smart contracts. Due to the shared nature of blockchains, understanding the usage of blockchain-based applications and the underlying network is crucial. Although log analysis is a well-established means, data extraction from blockchain platforms can be highly inconvenient and slow, not least due to the absence of logging libraries. To close the gap, we here introduce the Ethereum Logging Framework (ELF) which is highly configurable and available as open source. ELF supports users (i) in generating cost-efficient logging code readily embeddable into smart contracts and (ii) in extracting log analysis data into common formats regardless of whether the code generation has been used during development. We provide an overview of and rationale for the framework's features, outline implementation details, and demonstrate ELF's versatility based on three case studies from the public Ethereum blockchain.
Abstract Port Knocking is a method for authenticating clients through a closed stance firewall, and authorising their requested actions, enabling severs to offer services to authenticated clients, without opening ports on the firewall. Advances in port knocking have resulted in an increase in complexity in design, preventing port knocking solutions from realising their potential. This paper proposes a novel port knocking solution, named Crucible, which is a secure method of authentication, with high usability and features of stealth, allowing servers and services to remain hidden and protected. Crucible is a stateless solution, only requiring the client memorise a command, the server’s IP and a chosen password. The solution is forwarded as a method for protecting servers against attacks ranging from port scans, to zero-day exploitation. To act as a random oracle for both client and server, cryptographic hashes were generated through chaotic systems.
Jawad Ali, Ahmad Shahrafidz Khalid, Eiad Yafi, Shahrulniza Musa · 5 authors
Internet of Things (IoT) occupies a vital aspect of our everyday lives. IoT networks composed of smart-devices which communicate and transfer the information without the physical intervention of humans. Due to such proliferation and autonomous nature of IoT systems make these devices threatened and prone to a severe kind of threats. In this paper, we introduces a behavior capturing, and verification procedures in blockchain supported smart-IoT systems that can be able to show the trust-level confidence to outside networks. We defined a custom \emph{Behavior Monitor} and implement on a selected node that can extract the activity of each device and analyzes the behavior using deep machine learning strategy. Besides, we deploy Trusted Execution Technology (TEE) which can be used to provide a secure execution environment (enclave) for sensitive application code and data on the blockchain. Finally, in the evaluation phase we analyze various IoT devices data that is infected by Mirai attack. The evaluation results show the strength of our proposed method in terms of accuracy and time required for detection.
One of the crucial parts of the internet is the domain name system, which works as a phonebook of the internet. The protocol is designed to be fast, reliable, and not shielded with a security mechanism, DNSSEC which adds authentication later. However, threats utilising DNS such as DoS/DDoS are increasing daily. On the other hand, blockchain-based DNS is secure by design. By reviewing and comparing it with the current DNS and its ecosystem, it is concluded that blockchain currently has challenges that need to be addressed before it can be adapted as a replacement for the existing DNS.