Blockchain Technology and Related Security Risks: Towards a Seven-Layer Perspective and Taxonomy

被引:7
|
作者
Mollajafari, Sepideh [1 ]
Bechkoum, Kamal [1 ]
机构
[1] Univ Gloucestershire, Sch Comp & Engn, Cheltenham GL50 4AZ, England
关键词
blockchain; Ethereum; smart contract vulnerabilities; centralisation; one-owner control; SMART CONTRACTS; ATTACKS;
D O I
10.3390/su151813401
中图分类号
X [环境科学、安全科学];
学科分类号
08 ; 0830 ;
摘要
Blockchain technology can be a useful tool to address issues related to sustainability. From its initial foundation based on cryptocurrency to the development of smart contracts, blockchain technology promises significant business benefits for various industry sectors, including the potential to offer more trustworthy modes of governance, reducing the risks for environmental and economic crises. Notwithstanding its known benefits, and despite having some protective measures and security features, this emerging technology still faces significant security challenges within its different abstract layers. This paper classifies the critical cybersecurity threats and vulnerabilities inherent in smart contracts based on an in-depth literature review and analysis. From the perspective of architectural layering, each layer of the blockchain has its own corresponding security issues. In order to have a detailed look at the source of security vulnerabilities within the blockchain, a seven-layer architecture is used, whereby the various components of each layer are set out, highlighting the related security risks and corresponding countermeasures. This is followed by a taxonomy that establishes the inter-relationships between the vulnerabilities and attacks in a smart contract. A specific emphasis is placed on the issues caused by centralisation within smart contracts, whereby a "one-owner" controls access, thus threatening the very decentralised nature that blockchain is based upon. This work offers two main contributions: firstly, a general taxonomy that compiles the different vulnerabilities, types of attacks, and related countermeasures within each of the seven layers of the blockchain; secondly, a specific focus on one layer of the blockchain namely, the contract layer. A model application is developed that depicts, in more detail, the security risks within the contract layer, while enlisting the best practices and tools to use to mitigate against these risks. The findings point to future research on developing countermeasures to alleviate the security risks and vulnerabilities inherent to one-owner control in smart contracts.
引用
收藏
页数:24
相关论文
共 17 条
  • [1] Survey of security supervision on blockchain from the perspective of technology
    Wang, Yu
    Gou, Gaopeng
    Liu, Chang
    Cui, Mingxin
    Li, Zhen
    Xiong, Gang
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 60
  • [2] A Research Perspective on Security in Fog Computing Through Blockchain Technology
    Garg, Disha
    Bhatia, Komal Kumar
    Gupta, Sonali
    ARTIFICIAL INTELLIGENCE AND SUSTAINABLE COMPUTING FOR SMART CITY, AIS2C2 2021, 2021, 1434 : 91 - 104
  • [3] On the Integration of Artificial Intelligence and Blockchain Technology: A Perspective About Security
    Kuznetsov, Oleksandr
    Sernani, Paolo
    Romeo, Luca
    Frontoni, Emanuele
    Mancini, Adriano
    IEEE ACCESS, 2024, 12 : 3881 - 3897
  • [4] On the Integration of Artificial Intelligence and Blockchain Technology: A Perspective About Security
    Kuznetsov, Oleksandr
    Sernani, Paolo
    Romeo, Luca
    Frontoni, Emanuele
    Mancini, Adriano
    IEEE Access, 2024, 12 : 3881 - 3897
  • [5] A priority-based seven-layer strategy for energy management cooperation in a smart city integrated green technology
    Ben Arab, Marwa
    Rekik, Mouna
    Krichen, Lotfi
    APPLIED ENERGY, 2023, 335
  • [6] Towards Big Data Security Framework by Leveraging Fragmentation and Blockchain Technology
    Alhazmi, Hanan E.
    Eassa, Fathy E.
    Sandokji, Suhelah M.
    IEEE ACCESS, 2022, 10 : 10768 - 10782
  • [7] Integrating blockchain technology and cloud services in healthcare: a security and privacy perspective
    Yanmin Zhang
    Dan Wang
    Proceedings of the Indian National Science Academy, 2023, 89 : 837 - 850
  • [8] Integrating blockchain technology and cloud services in healthcare: a security and privacy perspective
    Zhang, Yanmin
    Wang, Dan
    PROCEEDINGS OF THE INDIAN NATIONAL SCIENCE ACADEMY, 2023, 89 (04): : 837 - 850
  • [9] Towards Secure Blockchain-enabled Cloud Computing: A Taxonomy of Security Issues and Recent Advances
    Liu, Shengli
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2023, 14 (08) : 917 - 926
  • [10] RETRACTED: Prevention of Business Risks of Internet Information Security Platforms Based on Blockchain Technology (Retracted Article)
    Yang, Bingqing
    COMPUTATIONAL INTELLIGENCE AND NEUROSCIENCE, 2022, 2022