A secure and auditable logging infrastructure based on a permissioned blockchain

被引:31
|
作者
Putz, Benedikt [1 ]
Menges, Florian [1 ]
Pernul, Guenther [1 ]
机构
[1] Univ Regensburg, Dept Informat Syst, Univ Str 31, D-93053 Regensburg, Germany
关键词
Log management; Secure logging; Log auditing; Permissioned blockchain; Digital forensics;
D O I
10.1016/j.cose.2019.101602
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information systems in organizations are regularly subject to cyber attacks targeting confidential data or threatening the availability of the infrastructure. In case of a successful attack it is crucial to maintain integrity of the evidence for later use in court. Existing solutions to preserve integrity of log records remain cost-intensive or hard to implement in practice. In this work we present a new infrastructure for log integrity preservation which does not depend upon trusted third parties or specialized hardware. The system uses a blockchain to store non-repudiable proofs of existence for all generated log records. An open-source prototype of the resulting log auditing service is developed and deployed, followed by a security and performance evaluation. The infrastructure represents a novel software-based solution to the secure logging problem, which unlike existing approaches does not rely on specialized hardware, trusted third parties or modifications to the logging source. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [31] Resilient, Auditable, and Secure IoT-Enabled Smart Inverter Firmware Amendments With Blockchain
    Akkaoui, Raifa
    Stefanov, Alexandru
    Palensky, Peter
    Epema, Dick H. J.
    IEEE INTERNET OF THINGS JOURNAL, 2024, 11 (05): : 8945 - 8960
  • [32] A Trustworthy Content Moderation Scheme Based on Permissioned Blockchain
    Niu, Yanhua
    Gao, Shuai
    Zhang, Hongke
    EMERGING NETWORKING ARCHITECTURE AND TECHNOLOGIES, ICENAT 2022, 2023, 1696 : 131 - 145
  • [33] A Blockchain Oracle Interoperability Technique for Permissioned Blockchain
    Alhussayen, Asma A.
    Jambi, Kamal
    Khemakhem, Maher
    Eassa, Fathy E.
    IEEE ACCESS, 2024, 12 : 68130 - 68148
  • [34] Secure and Scalable Permissioned Blockchain using LDE-P2P Networks
    Murad, Saydul Akbar
    Rahimi, Nick
    2023 10TH INTERNATIONAL CONFERENCE ON INTERNET OF THINGS: SYSTEMS, MANAGEMENT AND SECURITY, IOTSMS, 2023, : 111 - 116
  • [35] Distributed Framework of SWIFT System Based on Permissioned Blockchain
    Zhu J.-M.
    Ding Q.-Y.
    Gao S.
    Ruan Jian Xue Bao/Journal of Software, 2019, 30 (06): : 1594 - 1613
  • [36] On the Feasibility of Secure Logging for Industrial Control Systems Using Blockchain
    Schorradt, Stefan
    Bajramovic, Edita
    Freiling, Felix
    THIRD CENTRAL EUROPEAN CYBERSECURITY CONFERENCE (CECC 2019), 2019,
  • [37] Secure Event Logging using a Blockchain of Heterogeneous Computing Resources
    Koumidis, K.
    Kolios, P.
    Ellinas, G.
    Panayiotou, C. G.
    2019 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2019,
  • [38] Secure Sharing Architecture of Personal Healthcare Data Using Private Permissioned Blockchain for Telemedicine
    Murthy, Ch V. N. U. Bharathi
    Shri, M. Lawanya
    IEEE ACCESS, 2024, 12 : 106645 - 106657
  • [39] Economics of Permissioned Blockchain Adoption
    Iyengar, Garud
    Saleh, Fahad
    Sethuraman, Jay
    Wang, Wenjun
    MANAGEMENT SCIENCE, 2023, 69 (06) : 3415 - 3436
  • [40] vCubeChain: A scalable permissioned blockchain
    Freitas, Allan Edgard Silva
    Rodrigues, Luiz Antonio
    Duarte Jr, Elias Procopio
    AD HOC NETWORKS, 2024, 158