A Blockchain-Based Framework for Scalable and Trustless Delegation of Cyber Threat Intelligence

被引:2
作者
Dunnett, Kealan [1 ]
Pal, Shantanu [2 ]
Jadidi, Zahra [3 ]
Jurdak, Raja [1 ]
机构
[1] Queensland Univ Technol, Sch Comp Sci, Trusted Networks Lab, Brisbane, Qld 4000, Australia
[2] Deakin Univ, Sch Informat Technol, Melbourne, Vic 3125, Australia
[3] Griffith Univ, Sch Informat & Commun Technol, Gold Coast Campus, Nathan, Qld 4222, Australia
来源
2023 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY, ICBC | 2023年
关键词
Cyber Threat Intelligence; Information Sharing; Privacy; Trust; Delegation; Data Injection; Blockchain;
D O I
10.1109/ICBC56567.2023.10174885
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
CTI sharing is increasingly used by organisations to strengthen security. The sensitivity of CTI has led to research on trust-based sharing, yet most existing CTI sharing approaches only support static trust-based decisions or centralised trust evaluation, limiting their scalability and lead to centralised risk. This paper proposes a blockchain-based CTI sharing framework that relies on trustless delegates for dynamic trust-based decision-making and decentralised trust evaluation. To facilitate trustless delegation, our proposal allows CTI producers to intentionally inject false data on a periodic basis into the system to audit the behaviour of delegates. Moreover, unlike existing approaches, delegates within our framework facilitate sharing of CTI directly with consumers such that scalable CTI sharing occurs. The results of a qualitative evaluation of the proposed framework's security show that it is resilient to common privacy and trust concerns. Moreover, a quantitative evaluation of a proof-of-concept prototype using Ethereum show that the proposed framework is scalable and cost-effective.
引用
收藏
页数:9
相关论文
共 26 条
  • [1] Abu Md Sahrom, 2018, Indonesian Journal of Electrical Engineering and Computer Science, V10, P371
  • [2] ACSC, ACSCS REP
  • [3] Afanasev MY, 2018, PROC CONF OPEN INNOV, P3, DOI 10.23919/FRUCT.2018.8468296
  • [4] Allouche Y, 2021, Arxiv, DOI arXiv:2103.13158
  • [5] A Decentralized Review System for Data Marketplaces
    Avyukt, Anusha
    Ramachandran, Gowri
    Krishnamachari, Bhaskar
    [J]. 2021 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY (ICBC), 2021,
  • [6] Badsha S, 2020, 2020 10TH ANNUAL COMPUTING AND COMMUNICATION WORKSHOP AND CONFERENCE (CCWC), P317, DOI [10.1109/CCWC47524.2020.9031164, 10.1109/ccwc47524.2020.9031164]
  • [7] Benet J.., 2014, arXiv
  • [8] Blockchain for Internet of Things: A Survey
    Dai, Hong-Ning
    Zheng, Zibin
    Zhang, Yan
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (05) : 8076 - 8094
  • [9] A Trust Architecture for Blockchain in IoT
    Dedeoglu, Volkan
    Jurdak, Raja
    Putra, Guntur D.
    Dorri, Ali
    Kanhere, Salil S.
    [J]. PROCEEDINGS OF THE 16TH EAI INTERNATIONAL CONFERENCE ON MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES (MOBIQUITOUS'19), 2019, : 190 - 199
  • [10] Dunnett K., 2022, Challenges and Opportunities of Blockchain for Cyber Threat Intelligence Sharing, P1, DOI [10.1007/978-3-031-08270-2_1, DOI 10.1007/978-3-031-08270-2_1]