Assessing the Threat of Blockchain-based Botnets

被引:11
|
作者
Boeck, Leon [1 ]
Alexopoulos, Nikolaos [1 ]
Saracoglu, Emine [1 ]
Muehlhaeuser, Max [1 ]
Vasilomanolakis, Emmanouil [2 ]
机构
[1] Tech Univ Darmstadt, Darmstadt, Germany
[2] Aalborg Univ, Aalborg, Denmark
关键词
D O I
10.1109/ecrime47957.2019.9037600
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Time and time again the security community has faced novel threats that were previously never analyzed, sometimes with catastrophic results. To avoid this, proactive analysis of envisioned threats is of great importance. One such threat is blockchain-based botnets. Bitcoin, and blockchain-based decentralized cryptocurrencies in general, promise a fair and more transparent financial system. They do so by implementing an open and censorship-resistant atomic broadcast protocol that enables the maintenance of a global transaction ledger, known as a blockchain. In this paper, we consider how this broadcast protocol may be used for malicious behavior as a botnet command and control (C2) channel. Botmasters have been known to misuse broadcasting platforms, like social media, as C2 channels. However, these platforms lack the integral censorship-resistant property of decentralized cryptocurrencies. In this paper, we provide a comprehensive systematization of knowledge study on using blockchains as botnet C2 channels, generating a number of important insights. We set off by providing a critical analysis of the state of the art of blockchain-based botnets, along with an abstract model of such a system. We then examine the inherent limitations of the design, in an attempt to challenge the feasibility of such a botnet. With such limitations in mind, we move forward with an experimental analysis of the detectability of such botnets and discuss potential countermeasures. Contrary to previous work that proposed such botnets, we provide a broad overview of the associated risk and view the problem in relation to other existing botnet C2 channels. We conclude that despite its limitations, the blockchain, as a backup mechanism, practically renders attempts to suppress the control channel of a botnet futile. Thus, more focus should be put on detecting and disinfecting machines at the network edge (router) or even per-bot level.
引用
收藏
页码:15 / 25
页数:11
相关论文
共 50 条
  • [1] Detection and Blockchain-Based Collaborative Mitigation of Internet of Things Botnets
    Sajjad, Syed Muhammad
    Mufti, Muhammad Rafiq
    Yousaf, Muhammad
    Aslam, Waqar
    Alshahrani, Reem
    Nemri, Nadhem
    Afzal, Humaira
    Khan, Muhammad Asghar
    Chen, Chien-Ming
    Wireless Communications and Mobile Computing, 2022, 2022
  • [2] Blockchain-Based Threat Registry Platform
    de Diego, Santiago
    Goncalves, Carlos
    Lage, Oscar
    Mansell, Jason
    Kontoulis, Michael
    Moustakidis, Serafeim
    Guerra, Barbara
    Liapis, Angelos
    2019 IEEE 10TH ANNUAL INFORMATION TECHNOLOGY, ELECTRONICS AND MOBILE COMMUNICATION CONFERENCE (IEMCON), 2019, : 892 - 898
  • [3] Collaborative Blockchain-Based Detection of Distributed Denial of Service Attacks Based on Internet of Things Botnets
    Spathoulas, Georgios
    Giachoudis, Nikolaos
    Damiris, Georgios-Paraskevas
    Theodoridis, Georgios
    FUTURE INTERNET, 2019, 11 (11):
  • [4] Blockchain-Based Model for Incentivized Cyber Threat Intelligence Sharing
    Venckauskas, Algimantas
    Jusas, Vacius
    Barisas, Dominykas
    Misnevs, Boriss
    APPLIED SCIENCES-BASEL, 2024, 14 (16):
  • [5] A Blockchain-Based Incentive Mechanism for Sharing Cyber Threat Intelligence
    Ma, Xingbang
    Yu, Dongsheng
    Du, Yanhui
    Li, Lanting
    Ni, Wenkai
    Lv, Haibin
    ELECTRONICS, 2023, 12 (11)
  • [6] Metrics for Assessing Blockchain-based Healthcare Decentralized Apps
    Zhang, Peng
    Walker, Michael A.
    White, Jules
    Schmidt, Douglas C.
    Lenz, Gunther
    2017 IEEE 19TH INTERNATIONAL CONFERENCE ON E-HEALTH NETWORKING, APPLICATIONS AND SERVICES (HEALTHCOM), 2017,
  • [7] A Blockchain-Based Framework for Scalable and Trustless Delegation of Cyber Threat Intelligence
    Dunnett, Kealan
    Pal, Shantanu
    Jadidi, Zahra
    Jurdak, Raja
    2023 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY, ICBC, 2023,
  • [8] Blockchain-Based Cyber Threat Intelligence System Architecture for Sustainable Computing
    Cha, Jeonghun
    Singh, Sushil Kumar
    Pan, Yi
    Park, Jong Hyuk
    SUSTAINABILITY, 2020, 12 (16)
  • [9] Amazon Biobank: Assessing the Implementation of a Blockchain-Based Genomic Database
    Kimura, Leonardo T.
    Shiraishi, Felipe K.
    Andrade, Ewerton R.
    Carvalho, Tereza C. M. B.
    Simplicio Jr, Marcos A.
    IEEE ACCESS, 2024, 12 : 9632 - 9647
  • [10] Blockchain-Based Coordination: Assessing the Expressive Power of Smart Contracts
    Ciatto, Giovanni
    Mariani, Stefano
    Maffi, Alfredo
    Omicini, Andrea
    INFORMATION, 2020, 11 (01)