A Secure and Reliable Blockchain-based Audit Log System

被引:2
作者
Liu, Zhonghao [1 ]
Zhang, Xinwei [2 ]
Li, Guyue [2 ,5 ]
Cui, Helei [4 ]
Wang, Jiaheng [3 ]
Xiao, Bin [1 ]
机构
[1] Hong Kong Polytech Univ, Dept Comp, Hong Kong, Peoples R China
[2] Southeast Univ, Sch Cyber Sci & Engn, Nanjing, Peoples R China
[3] Southeast Univ, Natl Mobile Commun Reseach Lab, Nanjing, Peoples R China
[4] Northwestern Polytech Univ, Sch Comp Sci, Xian, Peoples R China
[5] Purple Mt Labs Network & Commun Secur, Nanjing, Peoples R China
来源
ICC 2024 - IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS | 2024年
关键词
Audit log system; Blockchain; Hyperledger Fabric; InterPlanetary File System (IPFS); NFT;
D O I
10.1109/ICC51166.2024.10623012
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The use of log files in digital forensics highlights the importance of ensuring their data integrity for auditing purposes. However, traditional centralized audit log systems face challenges in maintaining data integrity due to log injection attacks and single-point failures. Although blockchain technology can accurately process and replicate log files, existing blockchain-based audit log systems still suffer from security and reliability issues due to their weak threat models and limited scalability. To address these concerns, we propose a blockchain-based audit log system that ensures data integrity under a general threat model where a part of the nodes, including loggers and auditors, are untrusted. First, our proposed system resists collusion attacks by incorporating multiple nodes for system processes and utilizing smart contracts to enforce consensus algorithms. Second, to save blockchain storage space, we design an efficient log integrity proof method, which generates a sub-Non-Fungible Token (sub-NFT) for each log file and keeps it on the blockchain as integrity proof. The single-point failure problem is resolved by outsourcing log files to a distributed file system. To evaluate the proposed system, we implement a prototype based on Hyperledger Fabric. Experimental results show that our proof generation method can reduce storage space usage in comparison to other blockchain-based audit log systems, saving approximately 50% of space in Hyperledger Fabric. The security analysis proves that our system can ensure log file data integrity under the proposed threat model.
引用
收藏
页码:2010 / 2015
页数:6
相关论文
共 17 条
  • [1] Towards Blockchain-Driven, Secure and Transparent Audit Logs
    Ahmad, Ashar
    Saad, Muhammad
    Bassiouni, Mostafa
    Mohaisen, Aziz
    [J]. PROCEEDINGS OF THE 15TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS 2018), 2018, : 443 - 448
  • [2] A Prototype Evaluation of a Tamper-resistant High Performance Blockchain-based Transaction Log for a Distributed Database
    Aniello, Leonardo
    Baldoni, Roberto
    Gaetani, Edoardo
    Lombardi, Federico
    Margheri, Andrea
    Sassone, Vladimiro
    [J]. 2017 13TH EUROPEAN DEPENDABLE COMPUTING CONFERENCE (EDCC 2017), 2017, : 151 - 154
  • [3] Blockchain-Based Logging for the Cross-Border Exchange of eHealth Data in Europe
    Castaldo, Luigi
    Cinque, Vincenzo
    [J]. SECURITY IN COMPUTER AND INFORMATION SCIENCES, EURO-CYBERSEC 2018, 2018, 821 : 46 - 56
  • [4] On Scaling Decentralized Blockchains (A Position Paper)
    Croman, Kyle
    Decker, Christian
    Eyal, Ittay
    Gencer, Adem Efe
    Juels, Ari
    Kosba, Ahmed
    Miller, Andrew
    Saxena, Prateek
    Shi, Elaine
    Sirer, Emin Gun
    Song, Dawn
    Wattenhofer, Roger
    [J]. FINANCIAL CRYPTOGRAPHY AND DATA SECURITY, FC 2016, 2016, 9604 : 106 - 125
  • [5] Distributed Immutabilization of Secure Logs
    Cucurull, Jordi
    Puiggali, Jordi
    [J]. SECURITY AND TRUST MANAGEMENT, STM 2016, 2016, 9871 : 122 - 137
  • [6] DeLaRosa A., 2018, LOG MONITORING NOT T, V14
  • [7] Huang JS, 2018, IEEE INT CONF BIG DA, P3033, DOI 10.1109/BigData.2018.8622204
  • [8] System log clustering approaches for cyber security applications: A survey
    Landauer, Max
    Skopik, Florian
    Wurzenberger, Markus
    Rauber, Andreas
    [J]. COMPUTERS & SECURITY, 2020, 92
  • [9] ProvChain: A Blockchain-based Data Provenance Architecture in Cloud Environment with Enhanced Privacy and Availability
    Liang, Xueping
    Shetty, Sachin
    Tosh, Deepak
    Kamhoua, Charles
    Kwiat, Kevin
    Njilla, Laurent
    [J]. 2017 17TH IEEE/ACM INTERNATIONAL SYMPOSIUM ON CLUSTER, CLOUD AND GRID COMPUTING (CCGRID), 2017, : 468 - 477
  • [10] DBE-voting: A Privacy-preserving and Auditable Blockchain-based E-voting System
    Liu, Zhonghao
    Zhang, Xinwei
    Lao, Laphou
    Li, Guyue
    Xiao, Bin
    [J]. ICC 2023-IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS, 2023, : 6571 - 6577