Kyoungmin Kim, Youngin You, Mookyu Park, Kyungho Lee
Distributed Denial of Service (DDoS) attacks are intense and are targeted to major infrastructure, governments and military organizations in each country. There are a lot of mitigations about DDoS, and the concept of Content Delivery Network (CDN) has been able to avoid attacks on websites. However, since the existing CDN system is fundamentally centralized, it may be difficult to prevent DDoS. This paper describes the distributed CDN Schema using Private Blockchain which solves the problem of participation of existing transparent and unreliable nodes. This will explain DDoS mitigation that can be used by military and government agencies.
Manish Kumar, Ashish Kumar Singh, T. V. Suresh Kumar
We are living in the era of information technology. Our day to day life is heavily dependent on it and hence it's safe and secure functioning become very crucial and important. Every minute, there are thousands of cyber-attacks taking place around the world. Attackers are continuously evolving sophisticated and stealthy techniques to target the victim. They takes all the precautionary measures to remove attack traces such as system logs and related information on the victim systems so that they cannot be traced back. Attackers intentionally spread their activities over longer period of time to evade detection. To understand and identify such complex attack, it is required to maintain a secure log records over extended time period. However, preserving the log records for longer time is challenging issue. The system should also ensure the integrity of log files and logging process. In order to overcome these issues, in this paper we are proposing a secure log storage using Blockchain on Cloud platform. Blockchain technology will help to create tamper-proof audit logs. It provides proof of log manipulation and nonrepudiation. Cloud platform makes the overall system scalable and support for deep analysis.
Matteo Signorini, Matteo Pontecorvi, Waël Kanoun, Roberto Di Pietro
Anomaly detection tools play a role of paramount importance in protecting networks and systems from unforeseen attacks, usually by automatically recognizing and filtering out anomalous activities. In this paper we present ADvISE: the first Anomaly Detection tool for blockchaIn SystEms which leverages blockchain meta-data, named forks, in order to collect potentially malicious requests in the network/system while being resilient to eclipse attacks. ADvISE collects and analyzes malicious forks to build a threat database that enables detection and prevention of future attacks.
Jul 1, 2018·2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CPSCom) and IEEE Smart Data (SmartData)
Botnets provide the foundation for a wide range of malicious activities on the Internet. Sophisticated Command and Control (C&C) infrastructures aim to prevent the detection and takedown of botnets and therefore pose a big challenge in the battle against network attacks of all kinds. In this paper, we present Chain Channels, a method for hidden botnet communication that exploits the digital signatures used in blockchains to inject subliminal messages. We show how subliminal messages can be included in signatures and distributed in blockchain transactions to the bots. We also show how the keying material required for extracting the subliminal information can be transmitted privately to the bots while being stored on a public blockchain. As proof of concept, we inject a subliminal message and a key in the Bitcoin blockchain and show how this information can be extracted from the transactions. Our method allows to establish a hidden C&C infrastructure over blockchains and send instructions to all bots without leaving any suspicious communication activities. The method relies only on digital signatures and is therefore applicable to numerous blockchains. The subliminal communication can not be distinguished from legitimate transactions, and mitigation would require redesigning blockchains to use new subliminal-free signature schemes. Our method provides a general hidden distribution channel over block chains and can be also applied to other scenarios where information needs to be transmitted covertly. It scales extremely well with the number of receivers (i.e., bots), and subliminal messages can even be distributed over different blockchains to exploit specific features of blockchains such as low transaction cost or fast confirmation times or to further obfuscate the existence of the C&C communication.
AbedAlqader Swedan, Ahmad N. Khuffash, Othman Othman, Ahmed Awad
As technology evolves, more and more devices are connected to the Internet. The popularity and increasing significance of cryptocurriences are drawing attention, and crybercriminals are trying to utilize the resources and steal the processing power of these devices. It is highly likely that there are billions of devices that are maliciously mining cryptocurrency for the benefit of a cybercriminal without noticing the damage they may be causing. This paper is proposed because there is a huge need to professionally defend and protect against the misuse of assets in order to avoid losses, both financially and operationally, and how it is possible to mitigate with this rising trend.
Aaron Zimba, Zhaoshun Wang, Mwenge Mulenga, Nickson Herbert Odongo
The popularity of cryptocurrencies has continued to grow drastically over the past decade and this has drawn significant attention to various threat actors. Cybercriminals are now employing unconventional means to acquire cryptocurrencies at the expense of benign Internet users. This paper investigates the state-of-the-art crypto mining attacks by examining the malware code and the behavioral analysis upon execution. It examines the two most common attack approaches; web browser-based crypto mining which leverages JavaScript and installable binary crypto mining where the malware runs in memory. Furthermore, the paper investigates how cybercriminals endeavor to establish a persistence mechanism and avoid detection. The results from static and dynamic analysis uncover the techniques employed by the malware to exploit potential victims. Indicators of compromise are drawn from the uncovered artifacts which can be used as inputs to intrusion detection systems to help mitigate such cyber-attacks.
Uzair Javaid, Ang Kiang Siang, Muhammad Naveed Aman, Biplab Sikdar
Many IoT devices lack memory and computational complexities of modern computing devices, making them vulnerable to a wide range of cyber attacks. Among these, DDoS attacks are a growing concern in IoT. Such attacks are executed through the introduction of rogue devices and then using them and/or other compromised devices to facilitate DDoS attacks by generating relentless traffic. This paper aims to address DDoS security issues in IoT by proposing an integration of IoT devices with blockchain. This paper uses Ethereum, a blockchain variant, with smart contracts to replace the traditional centralized IoT infrastructure with a decentralized one. IoT devices are then required to access the network using smart contracts. The integration of IoT with Ethereum not only prevents rogue devices from gaining access to the server but also addresses DDoS attacks by using static resource allocation for devices.
This position paper describes how blockchains facilitate the implementation of distributed self-adaptive systems. We demonstrate how the master/slave decentralised control pattern for self-adaptive systems, integrated with a permissioned blockchain, can protect nodes of a network against attacks by continuously adapting the membership of an access control list. Whenever malicious behaviour is detected, consensus on an updated access control list is reached, and that node is removed from the network. Using a smart home, as an example, we demonstrate that a permissioned blockchain is able to maintain a consistent view of a network of Internet of Things (IoT) devices in the presence of malicious nodes.
Both “big data” and “analytics” have become popular keywords in many organizations. The power data analytics has on harnessing the increasing volumes, velocity and complexity of data in a world of constant change and disruptive technologies has been recognized. Many companies are making significant investments to better understand the impact of these capabilities on their businesses. One area with significant potential is the transformation of the audit. This project explores ways in which analytics can change and shape the work of accountants. \n \nAnomaly detection plays a pivotal role in data mining since most outlying points contain crucial information for further investigation. In the financial world which the Bitcoin network is a part of, anomaly detection can indicate fraud. Using data mining tools such as Regression, we simultaneously examine the relationship among variables whilst visually inspecting the data for possible outliers. By doing so, I have chosen the world’s leading cryptocurrency, Bitcoin. This project will conclude with an in-depth analysis on whether or not data analytics can shape how effectively, and secure accountants can audit transactions by implementing analytics tools into their daily protocols.
Protecting Critical Infrastructure (CI) against increasing cyber threats has become as crucial as it is complicated. To be effective in identifying and defeating cyber attacks, cyber analysts require novel distributed detection and reaction methodologies based on information security techniques that can automatically analyse incident reports and securely share analysis results between Critical Infrastructure stakeholders. Our goal is to provide solutions in real-time that could replace human input for cyber incident analysis tasks (triage) to classify cyber incident reports, find related reports in a fast and scalable way, eliminate irrelevant information, and automate reporting life- cycle management. Our effective and fast incident management method is based on artificial intelligence and can support cyber analysts in establishing cyber situational awareness, and allow them to quickly adopt suitable countermeasures in the case of an attack. In this paper, we evaluate deep autoencoder neural network supported by Blockchain technology as a system for incident classification and management, and assess its accuracy and performance. This approach should reduce the number of manual operations and save storage space. We used a Blockchain smart contract technique to provide an automated trusted system for incident management workflow that allows automatic acquisition, classification and enrichment of incident data. We demonstrate how the presented techniques can be applied to support incident handling tasks performed by security operation centres.
In order for malicious software to receive configuration information or commands, malware needs to be able to locate and connect to its owner. As hard-coded addresses are easy to block and thus render the malware installation inoperable, malware writers have turned to dynamically generated addresses. Domain generation algorithms (DGA) generate a list of candidate domain names, each valid for only a short time, at which the malware installation searches for its command & control (C&C) server. As DGAs generate a large list of potential domains - out of which one or a few is actually in use -, they leave a characteristic trace of many failed DNS lookups (NXDomain) in the network, and in result most DGAs can be efficiently detected. In this paper we describe an entirely new principle of domain generation, actively deployed in the Cerber ransomware, which finds and coordinates with its owner based on transaction information in the bitcoin blockchain. This allows the malware author to dynamically update the location of the server in realtime, and as the malware directly goes to the right location no longer generates a sequence of NXDomain responses. We describe the concept of coordination via the blockchain, and report results on a year-long observation of the assets used in the Cerber campaign.
Among various network attacks, botnet led attacks are considered as the most serious threats. A botnet, i.e., the network of compromised computers is able to perform large scale illegal activities such as Distributed Denial of Service attacks, click fraud, bitcoin mining etc. These attacks are considered as the major concern now-a-days. In this paper, we present a comprehensive review of botnets, their lifecycle and types. We also discuss the peer-to-peer botnet detection techniques' behaviors using various latest detection techniques.
Cyberattacks are nowadays moving rapidly. They are customized, multi-vector, staged in multiple flows and targeted. Moreover, new hacking playgrounds appeared to reach mobile network, modern architectures and smart cities. For that purpose, malware use different entry points and plug-ins. In addition, they are now deploying several techniques for obfuscation, camouflage and analysis resistance. On the other hand, antiviral protections are positioning innovative approaches exposing malicious indicators and anomalies, revealing assumptions of the limitations of the anti-antiviral mechanisms. Primarily, this paper exposes a state of art in computer virology and then introduces a new concept to create undetectable malware based on the blockchain technology. It summarizes techniques adopted by malicious software to avoid functionalities implemented for viral detection and presents the implementation of new viral techniques that leverage the blockchain network.
Igor D. Alvarenga, Gabriel Antonio F. Rebello, Otto Carlos M. B. Duarte
The integration of network function visualization (NFV) and service function chaining (SFC) adds intelligence to the core of the network. The programmability of the network core, however, raises new vulnerabilities and increases the number of victims, since a simple modification in the core can affect multiple network users. Thus, the provision of secure virtual network service functions (VNFs) is mandatory to guarantee a correct chaining of network functions. This paper proposes a blockchain-based architecture for secure management, configuration and migration of VNFs, which ensures: (i) immutability, non-repudiation, and auditability of the configuration update history; (ii) integrity and consistency of stored information; and (iii) the anonymity of VNFs, tenants, and configuration information. Furthermore, the proposed architecture guarantees the secure update and migration of configurations at the core of the network. A prototype of the proposed architecture using the Open Platform for NFV (OPNFV) indicates parameter trade-offs and performance bottlenecks.
Information security is the key to the development of modern Internet technology. The distributed mechanism, decentralized mechanism, password mechanism and scripted mechanism of the Blockchain present a completely new perspective for the development of Internet information security technology. The Blockchain technology redefines the storage and dissemination methods of the information in the network. Neither participant needs to know each other, and nor does it require third-party certification bodies to participate. It records, transmits and stores transferring activities of the information value by distributed technology, ensures that data is not tampered and forged based on an asymmetric cryptographic algorithm, enables all participants reached a consensus on the status of blockchain data information. And from the current industry research on blockchain technology, it expounds the application of blockchain technology in identity authentication, data protection and network security. The Blockchain technology will be a great driving force in the process of information security technology change, and will have a far-reaching impact on the expansion of information security.
Alexander Yakubov, Wazen M. Shbair, Anders Wallbom, David Sanda · 5 authors
Public-Key Infrastructure (PKI) is the cornerstone technology that facilitates secure information exchange over the Internet. However, PKI is exposed to risks due to potential failures of Certificate Authorities (CAs) that may be used to issue unauthorized certificates for end-users. Many recent breaches show that if a CA is compromised, the security of the corresponding end-users will be in risk. As an emerging solution, Blockchain technology potentially resolves the problems of traditional PKI systems - in particular, elimination of single point-of-failure and rapid reaction to CAs shortcomings. Blockchain has the ability to store and manage digital certificates within a public and immutable ledger, resulting in a fully traceable history log. In this paper we designed and developed a blockchain-based PKI management framework for issuing, validating and revoking X.509 certificates. Evaluation and experimental results confirm that the proposed framework provides more reliable and robust PKI systems with modest maintenance costs.
Due to their rapid growth and deployment, Internet of things (IoT) devices have become a central aspect of our daily lives. However, they tend to have many vulnerabilities which can be exploited by an attacker. Unsupervised techniques, such as anomaly detection, can help us secure the IoT devices. However, an anomaly detection model must be trained for a long time in order to capture all benign behaviors. This approach is vulnerable to adversarial attacks since all observations are assumed to be benign while training the anomaly detection model. In this paper, we propose CIoTA, a lightweight framework that utilizes the blockchain concept to perform distributed and collaborative anomaly detection for devices with limited resources. CIoTA uses blockchain to incrementally update a trusted anomaly detection model via self-attestation and consensus among IoT devices. We evaluate CIoTA on our own distributed IoT simulation platform, which consists of 48 Raspberry Pis, to demonstrate CIoTA's ability to enhance the security of each device and the security of the network as a whole.
Bitcoin cryptocurrency has risen in popularity. Therefore, it not only attracts users to use it, but also it attracts the malware developers to attack it. While online Bitcoin wallets allow users to conveniently store and manage their bitcoins, they are vulnerable to several attacks.
As the Internet of Things (IoT) develops and expands, management of IoT communications becomes a major challenge. A large number of IoT devices may be installed anywhere end users wish, then left unattended and be misused to attack others. In edge networks, it is difficult to properly prevent undesired communication without knowledge of the properties of an IoT service and its devices. In this paper, we argue that application service providers, developers, and network operators should 1) verify and know the authenticity of IoT services, devices, and their communications, and 2) prevent unwanted traffic from IoT devices in a trustworthy, scalable, and distributed manner. This paper proposes a Trust List that represents the distribution of trust among IoT-related stakeholders and provides autonomous enforcement of IoT traffic management at the edge networks by integrating blockchains and Software-Defined Networking (SDN). The principle of Trust List is automating the process of doubting, verifying, and trusting IoT services and devices to effectively prevent attacks and abuses. The proof of concept implementation and experiment of the Trust List using both public and private blockchains reveal its good practice and suggest studies for realistic deployment.