One of the crucial parts of the internet is the domain name system, which works as a phonebook of the internet. The protocol is designed to be fast, reliable, and not shielded with a security mechanism, DNSSEC which adds authentication later. However, threats utilising DNS such as DoS/DDoS are increasing daily. On the other hand, blockchain-based DNS is secure by design. By reviewing and comparing it with the current DNS and its ecosystem, it is concluded that blockchain currently has challenges that need to be addressed before it can be adapted as a replacement for the existing DNS.
Aneta Poniszewska-Marańda, Michał Pawlak, Jakub Guziur
There exist many different electronic voting solutions and each has its own set of advantages and disadvantages. Most of the existing systems suffer from inadequate transparency and auditability. However, recently introduced blockchain technology may provide a solution to these problems. In this paper, auditable blockchain voting system (ABVS) is presented. It combines existing voting approach and combines it with blockchain technology to create a supervised and remote internet voting system, which is transparent and audit capable. The paper describes the system's processes, components, model and results of initial testing.
A cryptocurrency is a decentralised digital currency that utilises blockchain technology to remove the role of a central authority. Monero is one of the cryptocurrencies that improves its anonymity by employing privacy-preserving cryptographic techniques, such as linkable ring signature. In this thesis, we explore three areas in Monero system that can cause anonymity problems. These areas are Monero transaction creation protocol, Monero protocol update, and Monero third-party services. We identify attack schemes to reduce honest users' transaction anonymity. We then investigate the impact of Monero protocol updates to transaction anonymity. Lastly, we study wallet service providers that can trace Monero transactions and mining pools that leak information.
Ordinos is a novel verifiable tally-hiding e-voting system. At its heart, a homomorphic encryption scheme and secure multi-party computation (MPC) are used to tally votes and securely determine the voting result, without necessarily revealing the full tally (e.g., the number of votes per candidate)The proof of concept implementation of Ordinos is based on a threshold variant of the Paillier encryption scheme and two MPC protocols for the comparison of encrypted numbers (greater-than and equality). Due to the threshold construction, the decryption key is shared among a set of trustees. The MPC protocols for comparison require precomputed encrypted randomness of certain shape. Formerly, a trusted party was employed to generate the key shares and randomness and distribute them to the trustees. In this thesis, the trusted party was replaced by MPC protocols that allow to generate the key shares and randomness among the trustees. The protocols provide security against malicious parties in the honest-majority setting. The key generation follows a proposal by Nishide and Sakurai (2010) that is based on verifiable secret sharings and zero-knowledge proofs for committed values. We introduce a few adaptations to reduce its runtime using mostly standard techniques. The generation of randomness is based on the Paillier encryption scheme as an arithmetic black box and standard zero-knowledge proofs for Paillier encrypted values. The protocols were implemented and their performance was evaluated in a local network. Most notablythe implemented key generation protocol for threshold Paillier showed an expected average runtime around 95 minutes for generating 2048-bit keys among 3 trustees with a threshold of 2. Since existing implementations provide security only in the semi-honest setting, this is the first time that an approach with security against malicious parties was implemented and evaluated. Overall, the distributed generation of both key shares and randomness takes considerably more time compared to the use of a trusted party, but avoids security risks and trust problems that occur with trusted parties.
Open access
Internet Traffic Analysis and Secure E-voting
Advanced Steganography and Watermarking Techniques
Mahmudul Hassan Ashik, Mirza Mohd Shahriar Maswood, Abdullah G. Alharbi, Deep Medhi
Blockchain is a public ledger which is distributed in nature and has become highly popular. Bitcoin is the most successful application of it. The reason behind Bitcoin's success lies in its Consensus mechanism which ensures the security from any kind of attack. Because of this, no dishonest miner can affect the chain to manipulate it according to their wish. Also, the double spending problem does not occur and there is no need to trust a third party in this network. The most common consensus protocol in bitcoin technology is Proof-of-Work (PoW) which entirely depends on the computation power of miners. Because of this dependency, Application-specific Integrated Circuits (ASIC) is designed for bitcoin mining. Thereafter, it has become a threat to its decentralized nature and has been monopolizing the validation of new blocks. It is not possible to halt the production of ASIC-based devices even if it threatens the decentralized applications. So, different types of consensus protocols are proposed to nullify this threat whereas all of them have failed to fully nullify it. ASIC devices are costly, so only a few miners can afford it and monopolize over blockchain network. In our work, Filtered Proof-of-Work (FPoW) is proposed and its ASIC-resistivity has been evaluated to make it a future-proof ASIC-resistant consensus protocol.
Although the launch of Internet Protocol version six (IPv6) addressed the issue of IPv4's address depletion, but also mandated the use of Internet Control Message Protocol version six (ICMPv6) messages in newly introduced features such as the Neighbor Discovery Protocol (NDP). This has exacerbated existing network attacks including ICMPv6-based Denial of Service (DoS) attacks and its variant form Distributed Denial of Service (DDoS) attack. Intrusion Detection Systems (IDS) aimed at tackling security issues raised by ICMPv6-based DoS and DDoS attacks have been reviewed by researchers and a general classification of existing IDSs was proposed as anomaly-based and signature-based. However, it is incredibly hard to see the overall picture of IDSs based on Machine Learning (ML) techniques with such a classification, as there is a lack of a more detailed view of the ML approach, classifiers, feature selection techniques, datasets, and different evaluation metrics. Nevertheless, recent developments in this relatively new field have not been covered such as ML-based IDSs using flow-based traffic representation. Therefore, this article specifically reviews and classifies IDSs based on ML techniques to detect ICMPv6-based DoS and DDoS attacks as single and hybrid classifiers. In addition, blockchain applicability in Collaborative IDS (CIDS) architecture based on the ensemble framework has been proposed as a solution to one of the open challenges for ICMPv6-based DoS and DDoS attacks detection problem. Moreover, this review also provides a classification of ICMPv6 vulnerabilities to DoS and DDoS attacks which would provide a reference resource for future researchers in this domain. To the best of the author's knowledge, this is the first review paper specifically focusing on IDSs based on ML techniques in this domain, as well as blockchain applicability as a possible research direction has been proposed to attract researcher's focus on building ensemble learning-based IDS models.
The Onion Router (Tor) is one of the major network systems that provide anonymous communication and censorship circumvention. Tor enables its users to surf the Internet, chat, and send messages anonymously; however, cyber attackers also exploit the system for circumventing criminal activity detection. Recently, various approaches that prevent or mitigate abuse of Tor have been proposed in the literature. This paper, which presents one of the approaches, addresses an IP traceback problem. In our model, onion routers that voluntarily participate in attacker tracing detect attack packets (packets carrying an attacker's code or data) recorded in the log files by sharing necessary information with an attacked server over an Ethereum blockchain network. The detection algorithm in this paper uses the statistics of packet travel and relay times and outputs attack-packet candidates. The proposed method attaches a reliability degree to each candidate, which is based on the upper bounds of its Type I and II error rates. A smart contract running on the blockchain network ranks the detection results from onion routers according to the reliability degrees.
The inseparable internet requirements and the endless stream of cyber-attacks have led to strong demand for trusted IP addresses. However, the existing collaborative DNS security schemes have the defects of low credibility and imperfect incentive mechanism. Enlightened by the Consortium blockchain technology, we propose a novel DNS Cache Resources Trusted Sharing Model, which can improve the credibility of DNS resolution results by establishing a complete chain of trust. Firstly, the consortium blockchain is introduced as the carrier of the peer-to-peer network to reduce the impact of illegal access and complicity tampering on the DNS cache credibility; Secondly, the evaluation index of the node credibility in the DNS cache sharing model is proposed, and the trust-based incentive mechanism is designed to reduce the impact of free-riding behavior and on the trusted performance of the system. The two indicators of node abnormal behavior similarity and roundtrip time between nodes are used to comprehensively evaluate the degree of recommendation of the node and serve as the basis for dynamic scheduling; Finally, we use the stochastic distributed decentralized storage mechanism to solve the problem of low efficiency in the consortium blockchain. The simulation results show that the model has certain advantages in ensuring the credibility of domain name resolution results, and maintains the ideal efficiency while ensuring trust.
Electronic voting solutions are built on complex cryptographic tools to guarantee security and fairness. Currently, those tools are based on hardness assumptions of discrete logarithm, factorization and other classical problems. While they are hard to break in classical computers, there are efficient quantum algorithms to solve using quantum computers of the near future. Thus, there is a need to develop voting protocols that are resistant to quantum attacks. Verifiable shuffling based voting systems are a popular use-case of mix-networks first proposed by Chaum four decades ago [Cha81] as a general tool for building anonymous communication systems. A decade later the quantum threat was known and since then only a few studies searched for post-quantum secure mix-nets. Recently, Costa, Martinez and Morillo introduced new arguments of shuffle for RLWE ciphertexts and how to prove the correctness of the shuffling without leaking sensitive info [CMM17]. In this thesis, we provide exact, shorter proof of Costa et al.’s lattice-based shuffling arguments. As a result, we obtain a practical non-interactive zero-knowledge proof having a runtime of 1 second per voter.
Identity is a tool that identifies a person or group and ensures that they are recognized by others. Personalidentification cards issued by the states to people contain specific information about the person given.Identity systems used for centuries are now digitalized, ID cards with chips and passports with chipshave entered our lives. In the past, only information such as name, surname and place of birth wereincluded in ID cards with chips and passports. But today, in addition to our personal information, itincludes our biometric information such as fingerprints, iris, digital signatures. Blockchain technology,which has entered our lives with the financial sector, offers application areas in different sectors andsubjects. Some of these are IoT (internet of things), security and reliability systems, copyrights, publicand health sectors. In this study, it has been mentioned about the advantages and the features obtainedby using blockchain technology in identity management. The purpose of this study; It is to ensure thesafe use of identity information thanks to the features provided by the block chain such as distributeddatabase called DLT (distributed ledger technology), peer-to-peer transmission, transparency andirreversible records. Also in this study, a software that can simulate blockchain technology was createdand an Android application that reads data with NFC (Near Field Communication) technology wasdeveloped. Thus, the process of adding the data in the ID card or passport to the block chain by readingthe data from NFC with the Android application can be performed.