A secure and auditable logging infrastructure based on a permissioned blockchain

被引:31
|
作者
Putz, Benedikt [1 ]
Menges, Florian [1 ]
Pernul, Guenther [1 ]
机构
[1] Univ Regensburg, Dept Informat Syst, Univ Str 31, D-93053 Regensburg, Germany
关键词
Log management; Secure logging; Log auditing; Permissioned blockchain; Digital forensics;
D O I
10.1016/j.cose.2019.101602
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Information systems in organizations are regularly subject to cyber attacks targeting confidential data or threatening the availability of the infrastructure. In case of a successful attack it is crucial to maintain integrity of the evidence for later use in court. Existing solutions to preserve integrity of log records remain cost-intensive or hard to implement in practice. In this work we present a new infrastructure for log integrity preservation which does not depend upon trusted third parties or specialized hardware. The system uses a blockchain to store non-repudiable proofs of existence for all generated log records. An open-source prototype of the resulting log auditing service is developed and deployed, followed by a security and performance evaluation. The infrastructure represents a novel software-based solution to the secure logging problem, which unlike existing approaches does not rely on specialized hardware, trusted third parties or modifications to the logging source. (C) 2019 Elsevier Ltd. All rights reserved.
引用
收藏
页数:10
相关论文
共 50 条
  • [41] Attacks on Permissioned Blockchain for IoT
    Pavithran, Deepa
    Angeles, Enrico
    Shibu, Charles
    Shaikh, Munavwar
    2021 4TH INTERNATIONAL CONFERENCE ON SIGNAL PROCESSING AND INFORMATION SECURITY (ICSPIS), 2021,
  • [42] A Permissioned Blockchain based Access Control System for IOT
    Islam, M. D. Azharul
    Madria, Sanjay K.
    2019 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN (BLOCKCHAIN 2019), 2019, : 469 - 476
  • [43] Permissioned Blockchain and Deep Learning for Secure and Efficient Data Sharing in Industrial Healthcare Systems
    Kumar, Randhir
    Kumar, Prabhat
    Tripathi, Rakesh
    Gupta, Govind P.
    Islam, A. K. M. Najmul
    Shorfuzzaman, Mohammad
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2022, 18 (11) : 8065 - 8073
  • [44] Secure and Privacy-Preserving Stored Surveillance Video Sharing atop Permissioned Blockchain
    Fitwi, Alem
    Chen, Yu
    30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,
  • [45] Permissionless and permissioned blockchain diffusion
    Helliar, Christine, V
    Crawford, Louise
    Rocca, Laura
    Teodori, Claudio
    Veneziani, Monica
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2020, 54
  • [46] Redactable Blockchain in the Permissioned Setting
    Peng, Chunying
    Xu, Haixia
    Liao, Huimei
    Tang, Jinling
    Tang, Tao
    SCIENCE OF CYBER SECURITY, SCISEC 2023, 2023, 14299 : 460 - 477
  • [47] Secure, Dynamic and Uncomplicated Licensing of Movies on a Blockchain Infrastructure
    Santos, Joao
    Amorim, Ivone
    Ulisses, Alexandre
    Lopes, Joao Correia
    Filipe, Vasco
    2023 INTERNATIONAL CONFERENCE ON INFORMATION NETWORKING, ICOIN, 2023, : 152 - 157
  • [48] Secure Log Storage Using Blockchain and Cloud Infrastructure
    Kumar, Manish
    Singh, Ashish Kumar
    Kumar, T. V. Suresh
    2018 9TH INTERNATIONAL CONFERENCE ON COMPUTING, COMMUNICATION AND NETWORKING TECHNOLOGIES (ICCCNT), 2018,
  • [49] Building Secure Infrastructure for Cloud Computing using Blockchain
    Sharma, Shweta Gaur
    Ahuja, Laxmi
    Goyal, D. P.
    PROCEEDINGS OF THE 2018 SECOND INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTING AND CONTROL SYSTEMS (ICICCS), 2018, : 1985 - 1988
  • [50] A Blockchain-Based Hybrid Architecture for Auditable Consent Management
    Can, Ozgu
    Dag, Tunahan
    Kantarcioglu, Murat
    IEEE ACCESS, 2024, 12 : 100419 - 100445