Blockchain Papers

Follow blockchain research across journals, conferences, and preprint repositories.

1,259 papersLast indexed Aug 31, 2026
Search papers

Paper index

1,259 results · page 53 of 53

Clear filters
Aug 18, 2010·Sciyo eBooks
9 cites
Bayesian Networks for Network Intrusion Detection

Pablo Andrés García, Igor Santos

As the use of Internet grows beyond all boundaries, the number of menaces rises to become subject of concern and increasing research. Against this, Network Intrusion Detection Systems (NIDS) monitor local networks to separate legitimate from dangerous behaviours. According to their capabilities and goals, NIDS are divided into misuse detection systems (which aim to detect well-known attacks) and anomaly detection systems (which aim to detect zero-day attacks). So far, no system to our knowledge combines advantages of both without any of their disadvantages. Moreover, the use of historical data for analysis or sequential adaptation is usually ignored, missing in this way the possibility of anticipating the behaviour of the target system. ESIDE-Depian, a Bayesian-networks-based misuse and anomaly detection system. In another work, we detailed the composition of the Bayesian network, its training methodology and showed general performance results. Here we have focused on evaluating the integration of misuse and anomaly detection. To this end, we have adopted Snort (a well-known misuse detector) as misuse detector trainer so the Bayesian Network of five experts is able to react against both misuse and anomalies. The Bayesian experts are devoted to the analysis of different network protocol aspects and obtain the common knowledge model by means of separated Snort-driven automated learning process Since ESIDE-Depian has passed the experiments brilliantly, it is possible to conclude that ESIDE-Depian using of Bayesian Networking concepts allows to confirm an excellent basis for paradigm unifying Network Intrusion Detection, providing not only stable Misuse Detection but also effective Anomaly Detection capabilities, with one only flexible knowledge representation model and a well-proofed inference and adaptation bunch of methods. On the other hand, the Bayesian approach also enables to implement powerful features over it, such as Dynamic-Bayesian-Network-based full representation of time, in order to accomplish totally-characterised connection tracking and low level chronological event correlation, or explanation tracking of the inferred cause-effect reasoning processes. Furthermore, contrary to other approaches such as Neural Networks, Bayesian networks allow administrative managing of inner information structures, so specific relationships among packet detection parameters and final conclusion can be explained, in a white-box manner. Moreover, it is not only possible to recover reasoning information, but also to act on both Bayesian network

Open access
Network Security and Intrusion Detection
Bayesian Modeling and Causal Inference
Anomaly Detection Techniques and Applications
Original source
Jan 1, 2008·IGI Global eBooks
3 cites
Security of Mobile Code

Zbigniew Kotulski, Aneta Zwierko

The recent development in the mobile technology (mobile phones, middleware, wireless networks, etc.) created a need for new methods of protecting the code transmitted through the network. The oldest and the simplest mechanisms concentrate more on integrity of the code itself and on the detection of unauthorized manipulation. The newer solutions not only secure the compiled program, but also the data, that can be gathered during its “journey,” and even the execution state. Some other approaches are based on prevention rather than detection. In this chapter we present a new idea of securing mobile agents. The proposed method protects all components of an agent: the code, the data, and the execution state. The proposal is based on a zero-knowledge proof system and a secure secret sharing scheme, two powerful cryptographic primitives. Next, the chapter includes security analysis of the new method and its comparison to other currently more widespread solutions. Finally, we propose a new direction of securing mobile agents by straightening the methods of protecting integrity of the mobile code with risk analysis and a reputation system that helps avoiding a high-risk behavior.Request access from your librarian to read this chapter's full text.

3 source records
Mobile Agent-Based Network Management
Network Security and Intrusion Detection
Distributed systems and fault tolerance
Original source
Jan 1, 2007·International journal of network security
6 cites
Integrity of mobile agents: a new approach.

Aneta Zwierko, Zbigniew Kotulski

The recent developments in the mobile technology (mobile phones, middleware) created a need for new methods of protecting the code transmitted through the network. The oldest and the simplest mechanisms concentrate more on integrity of the code itself and on the detection of unauthorized manipulation. The newer solutions not only secure the compiled program, but also the data, that can be gathered during its journey and even the execution state. Some other approaches base on prevention rather than detection. This paper describes a new idea of securing mobile agents. The presented method protects all: the code, the data and the execution state. The proposal is based on a zero-knowledge proof system and a secure secret sharing scheme, two powerful cryptographic primitives. The paper also includes security analysis of the new method and comparison to currently most widespread solutions.

Mobile Agent-Based Network Management
Network Security and Intrusion Detection
Peer-to-Peer Network Technologies
Original source
Sep 1, 2006·Zenodo (CERN European Organization for Nuclear Research)
5 cites
Agent-Based Offline Electronic Voting

Mehmet Tahir Sandıkkaya, Bülent Örencik

Many electronic voting systems, classified mainly as homomorphic cryptography based, mix-net based and blind signature based, appear after the eighties when zero knowledge proofs were introduced. The common ground for all these three systems is that none of them works without real time cryptologic calculations that should be held on a server. As far as known, the agent-based approach has not been used in a secure electronic voting system. In this study, an agent-based electronic voting schema, which does not contain real time calculations on the server side, is proposed. Conventional cryptologic methods are used in the proposed schema and some of the requirements of an electronic voting system are constructed within the schema. The schema seems quite secure if the used cryptologic methods and agents are secure. In this paper, proposed schema will be explained and compared with already known electronic voting systems.

Open access
2 source records
Internet Traffic Analysis and Secure E-voting
Cryptography and Data Security
Network Security and Intrusion Detection
Original source
Aug 3, 2005·Third International Conference on Information Technology and Applications (ICITA'05)
5 cites
Distributed Denial of Service Attacks and Anonymous Group Authentication on the Internet

Ashutosh Saxena, Ben Soh

Authentication forms the basis for most applications on the Internet. However, at the IP level, no solid mechanism yet exists for detecting 'spoofed' IP packets. The need for authenticating source IP addresses has become eminent with the advent of many ingenious DDoS attacks. In this paper, we propose a type of authentication scheme based on group (or multi party) signatures and discuss applications of such a scheme in preventing and detecting many types of DDoS attacks found on the Internet. Group signatures authenticate groups of senders rather than individuals and using such a scheme, senders can prove membership of a particular group without having to reveal their individual identity. The main idea behind our approach is to combine senders into large groups to reduce the amount of keying information kept in core routers. Our scheme also presents a method for secure routing protocols in general. Using our scheme, several autonomous networks can exercise policies on granting or denying routing privileges to other interconnected networks. Essentially, our protocol uses the concept of 'Non-interactive zero knowledge proofs of membership'

Internet Traffic Analysis and Secure E-voting
Network Security and Intrusion Detection
Security in Wireless Sensor Networks
Original source
Jun 29, 2005·arXiv (Cornell University)
2 cites
Security of mobile agents: a new concept of the integrity protection

Aneta Zwierko, Zbigniew Kotulski

The recent developments in the mobile technology (mobile phones, middleware) created a need for new methods of protecting the code transmitted through the network. The proposed mechanisms not only secure the compiled program, but also the data, that can be gathered during its "journey". The oldest and the simplest methods are more concentrated on integrity of the code itself and on the detection of unauthorized manipulation. Other, more advanced proposals protect not only the code but also the execution state and the collected data. The paper is divided into two parts. The first one is mostly devoted to different methods of securing the code and protecting its integrity; starting from watermarking and fingerprinting, up to methods designed specially for mobile agent systems: encrypted function, cryptographic traces, time limited black-box security, chained-MAC protocol, publicly-verifiable chained digital signatures The second part presents new concept for providing mobile agents with integrity protection, based on a zero-knowledge proof system.

Open access
2 source records
cs.CR
Mobile Agent-Based Network Management
Network Security and Intrusion Detection
Original source
Nov 7, 2002·Vehicular Technology Conference Fall 2000. IEEE VTS Fall VTC2000. 52nd Vehicular Technology Conference (Cat. No.00CH37152)
0 cites
Enhancing authentication mechanism with mobile agent in mobile communication system

Wei Deng, Mingqi Chen, Bo Ai

In order to be competitive, telecommunications service providers need new technologies that facilitate the rapid introduction of new services and resolve the problems how to use the services safely. This paper introduces a network platform based on mobile agent and provides a security mechanism based on zero knowledge proof in the mobile communication system. In this way, service providers can provide the new services rapidly, expediently and safely.

Mobile Agent-Based Network Management
Network Security and Intrusion Detection
Internet Traffic Analysis and Secure E-voting
Original source
Jan 1, 2000·IT Professional
8 cites
Developing a distributed system for infrastructure protection

George Cybenko, Guofei Jiang

Your business increasingly relies on computer-controlled systems vulnerable to intrusion and destruction. The recent distributed denial of service attacks against e-commerce companies showed that this vulnerability extends beyond your own corporate networks: the very infrastructure of the Internet is at risk. When infoterrorists use the networks' high connectivity and low security to launch attacks against critical information infrastructure systems, they can not only disrupt global e-commerce and communications, but can also adversely affect other critical infrastructure services such as energy, transportation, health care, finance, and water supply. How can organizations protect these systems from infoterrorism? They must leverage modern information technologies to create an infrastructure protection process that can operate quickly and seamlessly. We propose a six-stage protection process that involves intelligence gathering, analysis, interdiction, detection, response, and recovery. To implement this process, we've designed an underlying Web-like architecture that will serve as a platform for the decentralized monitoring and management of critical infrastructures.

Information and Cyber Security
Network Security and Intrusion Detection
Advanced Malware Detection Techniques
Original source