A Blockchain-Based Framework for Scalable and Trustless Delegation of Cyber Threat Intelligence

被引:2
|
作者
Dunnett, Kealan [1 ]
Pal, Shantanu [2 ]
Jadidi, Zahra [3 ]
Jurdak, Raja [1 ]
机构
[1] Queensland Univ Technol, Sch Comp Sci, Trusted Networks Lab, Brisbane, Qld 4000, Australia
[2] Deakin Univ, Sch Informat Technol, Melbourne, Vic 3125, Australia
[3] Griffith Univ, Sch Informat & Commun Technol, Gold Coast Campus, Nathan, Qld 4222, Australia
关键词
Cyber Threat Intelligence; Information Sharing; Privacy; Trust; Delegation; Data Injection; Blockchain;
D O I
10.1109/ICBC56567.2023.10174885
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
CTI sharing is increasingly used by organisations to strengthen security. The sensitivity of CTI has led to research on trust-based sharing, yet most existing CTI sharing approaches only support static trust-based decisions or centralised trust evaluation, limiting their scalability and lead to centralised risk. This paper proposes a blockchain-based CTI sharing framework that relies on trustless delegates for dynamic trust-based decision-making and decentralised trust evaluation. To facilitate trustless delegation, our proposal allows CTI producers to intentionally inject false data on a periodic basis into the system to audit the behaviour of delegates. Moreover, unlike existing approaches, delegates within our framework facilitate sharing of CTI directly with consumers such that scalable CTI sharing occurs. The results of a qualitative evaluation of the proposed framework's security show that it is resilient to common privacy and trust concerns. Moreover, a quantitative evaluation of a proof-of-concept prototype using Ethereum show that the proposed framework is scalable and cost-effective.
引用
收藏
页数:9
相关论文
共 50 条
  • [21] OTI-IoT: A Blockchain-based Operational Threat Intelligence Framework for Multi-vector DDoS Attacks
    Aguru, Aswani
    Erukala, Suresh
    ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2024, 24 (03)
  • [22] Trustless Framework for Iterative Double Auction Based on Blockchain
    Nguyen, Truc D. T.
    Thai, My T.
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM, PT I, 2019, 304 : 3 - 22
  • [23] Block Hunter: Federated Learning for Cyber Threat Hunting in Blockchain-Based IIoT Networks
    Yazdinejad, Abbas
    Dehghantanha, Ali
    Parizi, Reza M.
    Hammoudeh, Mohammad
    Karimipour, Hadis
    Srivastava, Gautam
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (11) : 8356 - 8366
  • [24] Blockchain-Based Threat Registry Platform
    de Diego, Santiago
    Goncalves, Carlos
    Lage, Oscar
    Mansell, Jason
    Kontoulis, Michael
    Moustakidis, Serafeim
    Guerra, Barbara
    Liapis, Angelos
    2019 IEEE 10TH ANNUAL INFORMATION TECHNOLOGY, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (IEMCON), 2019, : 892 - 898
  • [25] Cyber threat intelligence challenges: Leveraging blockchain intelligence with possible solution
    Saxena, Rashi
    Gayathri, E.
    MATERIALS TODAY-PROCEEDINGS, 2022, 51 : 682 - 689
  • [26] Assessing the Threat of Blockchain-based Botnets
    Boeck, Leon
    Alexopoulos, Nikolaos
    Saracoglu, Emine
    Muehlhaeuser, Max
    Vasilomanolakis, Emmanouil
    2019 APWG SYMPOSIUM ON ELECTRONIC CRIME RESEARCH (ECRIME), 2019, : 15 - 25
  • [27] Neural Network and Blockchain Based Technique for Cyber Threat Intelligence and Situational Awareness
    Graf, Roman
    King, Ross
    2018 10TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT (CYCON X): MAXIMISING EFFECTS, 2018, : 409 - 425
  • [28] Private blockchain-based encryption framework using computational intelligence approach
    Ghazal, Taher M.
    Hasan, Mohammad Kamrul
    Abdullah, Siti Norul Huda Sheikh
    Bakar, Khairul Azmi Abu
    Al Hamadi, Hussam
    EGYPTIAN INFORMATICS JOURNAL, 2022, 23 (04) : 69 - 75
  • [29] Blockchain-based IoT-Cloud Authorization and Delegation
    Tapas, Nachiket
    Merlino, Giovanni
    Longo, Francesco
    2018 IEEE INTERNATIONAL CONFERENCE ON SMART COMPUTING (SMARTCOMP 2018), 2018, : 411 - 416
  • [30] A Blockchain-based Medical Data Marketplace with Trustless Fair Exchange and Access Control
    Alsharif, Ahmad
    Nabil, Mahmoud
    2020 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2020,