A secure and auditable logging infrastructure based on a permissioned blockchain

被引:31
|
作者
Putz, Benedikt [1 ]
Menges, Florian [1 ]
Pernul, Guenther [1 ]
机构
[1] Univ Regensburg, Dept Informat Syst, Univ Str 31, D-93053 Regensburg, Germany
关键词
Log management; Secure logging; Log auditing; Permissioned blockchain; Digital forensics;
D O I
10.1016/j.cose.2019.101602
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information systems in organizations are regularly subject to cyber attacks targeting confidential data or threatening the availability of the infrastructure. In case of a successful attack it is crucial to maintain integrity of the evidence for later use in court. Existing solutions to preserve integrity of log records remain cost-intensive or hard to implement in practice. In this work we present a new infrastructure for log integrity preservation which does not depend upon trusted third parties or specialized hardware. The system uses a blockchain to store non-repudiable proofs of existence for all generated log records. An open-source prototype of the resulting log auditing service is developed and deployed, followed by a security and performance evaluation. The infrastructure represents a novel software-based solution to the secure logging problem, which unlike existing approaches does not rely on specialized hardware, trusted third parties or modifications to the logging source. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [1] A Secure Permissioned Blockchain Based System for Trademarks
    Showkatramani, Girish J.
    Khatri, Nidhi
    Landicho, Arlene
    Layog, Darwin
    2019 IEEE INTERNATIONAL CONFERENCE ON DECENTRALIZED APPLICATIONS AND INFRASTRUCTURES (DAPPCON), 2019, : 135 - 139
  • [2] Auditable Blockchain Rewriting in Permissioned Setting With Mandatory Revocability for IoT
    Shao, Wei
    Wang, Jinpeng
    Wang, Lianhai
    Jia, Chunfu
    Xu, Shujiang
    Zhang, Shuhui
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (24): : 21322 - 21336
  • [3] DASLog: Decentralized Auditable Secure Logging for UAV Ecosystems
    Sarenche, Roozbeh
    Aghili, Farhad
    Yoshizawa, Takahito
    Singelee, Dave
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (23): : 20264 - 20284
  • [4] Permissioned Blockchain Frame for Secure Federated Learning
    Sun, Jin
    Wu, Ying
    Wang, Shangping
    Fu, Yixue
    Chang, Xiao
    IEEE COMMUNICATIONS LETTERS, 2022, 26 (01) : 13 - 17
  • [5] A Secure IoT Data Communication and Sharing Framework Based on Permissioned Blockchain
    Refat, Raihanul Islam
    Hannan, Md Abdul
    Hashem, M. M. A.
    2020 IEEE REGION 10 SYMPOSIUM (TENSYMP) - TECHNOLOGY FOR IMPACTFUL SUSTAINABLE DEVELOPMENT, 2020, : 1312 - 1316
  • [6] Decentralized genomics audit logging via permissioned blockchain ledgering
    Pattengale, Nicholas D.
    Hudson, Corey M.
    BMC MEDICAL GENOMICS, 2020, 13 (Suppl 7)
  • [7] Decentralized genomics audit logging via permissioned blockchain ledgering
    Nicholas D. Pattengale
    Corey M. Hudson
    BMC Medical Genomics, 13
  • [8] SPDS: A Secure and Auditable Private Data Sharing Scheme for Smart Grid Based on Blockchain
    Wang, Yuntao
    Su, Zhou
    Zhang, Ning
    Chen, Jianfei
    Sun, Xin
    Ye, Zhiyuan
    Zhou, Zhenyu
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2021, 17 (11) : 7688 - 7699
  • [9] Secure Logging for Auditable File System using Separate Virtual Machines
    Zhao, Siqin
    Chen, Kang
    Zheng, Weimin
    2009 IEEE INTERNATIONAL SYMPOSIUM ON PARALLEL AND DISTRIBUTED PROCESSING WITH APPLICATIONS, PROCEEDINGS, 2009, : 153 - 160
  • [10] Permissioned Blockchain-Based Secure and Privacy-Preserving Data Sharing Protocol
    Wang, Zhiwei
    Chen, Qingqing
    Liu, Lei
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (12) : 10698 - 10707