A secure and auditable logging infrastructure based on a permissioned blockchain

被引:31
|
作者
Putz, Benedikt [1 ]
Menges, Florian [1 ]
Pernul, Guenther [1 ]
机构
[1] Univ Regensburg, Dept Informat Syst, Univ Str 31, D-93053 Regensburg, Germany
关键词
Log management; Secure logging; Log auditing; Permissioned blockchain; Digital forensics;
D O I
10.1016/j.cose.2019.101602
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information systems in organizations are regularly subject to cyber attacks targeting confidential data or threatening the availability of the infrastructure. In case of a successful attack it is crucial to maintain integrity of the evidence for later use in court. Existing solutions to preserve integrity of log records remain cost-intensive or hard to implement in practice. In this work we present a new infrastructure for log integrity preservation which does not depend upon trusted third parties or specialized hardware. The system uses a blockchain to store non-repudiable proofs of existence for all generated log records. An open-source prototype of the resulting log auditing service is developed and deployed, followed by a security and performance evaluation. The infrastructure represents a novel software-based solution to the secure logging problem, which unlike existing approaches does not rely on specialized hardware, trusted third parties or modifications to the logging source. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [21] SLC: A Permissioned Blockchain for Secure Distributed Machine Learning against Byzantine Attacks
    Liang, Lun
    Cao, Xianghui
    Zhang, Jun
    Sun, Changyin
    2020 CHINESE AUTOMATION CONGRESS (CAC 2020), 2020, : 7073 - 7078
  • [22] Distributed Storage System based on Permissioned Blockchain
    Nygaard, Racin
    Meling, Hein
    Jehl, Leander
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 338 - 340
  • [23] Building cryptotokens based on permissioned blockchain framework
    Anyshchenko, Oleksandr
    Bohuslayskyi, Ivan
    Kruglik, Stanislav
    Madhwal, Yash
    Ostrovsky, Alex
    Yanovich, Yury
    2019 IEEE 90TH VEHICULAR TECHNOLOGY CONFERENCE (VTC2019-FALL), 2019,
  • [24] DNS Service Model Based on Permissioned Blockchain
    Shen, Yantao
    Lu, Yang
    Wang, Zhili
    Xv, Xin
    Qi, Feng
    Xing, Ningzhe
    Zhao, Ziyu
    INTELLIGENT AUTOMATION AND SOFT COMPUTING, 2021, 27 (01): : 259 - 268
  • [25] Initial Public Offering (IPO) on Permissioned Blockchain using Secure Multiparty Computation
    Benhamouda, Fabrice
    De Caro, Angelo
    Halevi, Shai
    Halevi, Tzipora
    Jutla, Charanjit
    Manevich, Yacov
    Zhang, Qi
    2019 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN (BLOCKCHAIN 2019), 2019, : 91 - 98
  • [26] BGPChain: Constructing a secure, smart, and agile routing infrastructure based on blockchain
    Yan, Zhiwei
    Lee, Jong-Hyouk
    ICT EXPRESS, 2021, 7 (03): : 376 - 379
  • [27] Traceability in Permissioned Blockchain
    Mitani, Tatsuo
    Otsuka, Akira
    IEEE ACCESS, 2020, 8 : 21573 - 21588
  • [28] Bring Trust to Edge: Secure and Decentralized IoT Framework with BFT and Permissioned Blockchain
    Wu, Yusen
    Liao, Jinghui
    Nguyen, Phuong
    Shi, Weisong
    Yesha, Yelena
    2022 IEEE INTERNATIONAL CONFERENCE ON EDGE COMPUTING & COMMUNICATIONS (IEEE EDGE 2022), 2022, : 104 - 113
  • [29] Using Secure Multi-Party Computation to Protect Privacy on a Permissioned Blockchain
    Zhou, Jiapeng
    Feng, Yuxiang
    Wang, Zhenyu
    Guo, Danyi
    SENSORS, 2021, 21 (04) : 1 - 17
  • [30] EDISON: A Blockchain-based Secure and Auditable Orchestration Framework for Multi-domain Software Defined Networks
    Balachandran, Chandrasekar
    Puneet, A. C.
    Ramachandran, Gowri
    Krishnamachari, Bhaskar
    2020 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN (BLOCKCHAIN 2020), 2020, : 144 - 153