Cyber-Security Risk Assessment Framework for Blockchains in Smart Mobility

被引:13
作者
Al Mallah, Ranwa [1 ]
Lopez, David [2 ]
Farooq, Bilal [1 ]
机构
[1] Ryerson Univ, Lab Innovat Transportat, Toronto, ON M5G 1G3, Canada
[2] Univ Nacl Atonoma Mexico, Inst Ingn, Mexico City 04510, DF, Mexico
来源
IEEE OPEN JOURNAL OF INTELLIGENT TRANSPORTATION SYSTEMS | 2021年 / 2卷
关键词
Blockchains; Peer-to-peer computing; Risk management; Transportation; Security; Smart contracts; Privacy; blockchain; cyber security; mobility; risk; vulnerabilities; INTERNET; THINGS;
D O I
10.1109/OJITS.2021.3106863
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Use of distributed ledger technologies like blockchain is becoming more common in transportation/mobility ecosystems. However, cyber-security failures may occur at places where the blockchain system connects with the real world. In this paper, we propose a novel risk assessment framework for blockchain applications in smart mobility. We aim at systematically quantifying the risk by presenting ordinal values because although vulnerabilities exist in a system, it's the probability that they can be exploited and the impact of this exploitation that determine if in fact, the vulnerability corresponds to a significant risk. As a case study, we carry out an analysis in terms of quantifying the risk associated to a multi-layered Blockchain framework for Smart Mobility Data-markets (BSMD). We first construct an actor-based analysis to determine the impact of the attacks. Then, a scenario-based analysis determines the probability of occurrence of each threat. Finally, a combined analysis is developed to determine which attack outcomes have the highest risk. In the case study of the public permissioned BSMD, the outcomes of the risk analysis highlight the highest risk factors according to their impact on the victims in terms of monetary, privacy, integrity and trust. The analysis uncovers specific blockchain technology security vulnerabilities in the transportation ecosystem by exposing new attack vectors.
引用
收藏
页码:294 / 311
页数:18
相关论文
共 32 条
[1]  
Al Mallah Ranwa, 2020, CRYBLOCK 2020. Proceedings of the 3rd Workshop on Cryptocurrencies and Blockchains for Distributed Systems, P29, DOI 10.1145/3410699.3413794
[2]   Vulnerabilities on Hyperledger Fabric [J].
Andola, Nitish ;
Raghav ;
Gogoi, Manas ;
Venkatesan, S. ;
Verma, Shekhar .
PERVASIVE AND MOBILE COMPUTING, 2019, 59
[3]   Hyperledger Fabric: A Distributed Operating System for Permissioned Blockchains [J].
Androulaki, Elli ;
Barger, Artem ;
Bortnikov, Vita ;
Cachin, Christian ;
Christidis, Konstantinos ;
De Caro, Angelo ;
Enyeart, David ;
Ferris, Christopher ;
Laventman, Gennady ;
Manevich, Yacov ;
Muralidharan, Srinivasan ;
Murthy, Chet ;
Binh Nguyen ;
Sethi, Manish ;
Singh, Gari ;
Smith, Keith ;
Sorniotti, Alessandro ;
Stathakopoulou, Chrysoula ;
Vukolic, Marko ;
Cocco, Sharon Weed ;
Yellick, Jason .
EUROSYS '18: PROCEEDINGS OF THE THIRTEENTH EUROSYS CONFERENCE, 2018,
[4]   Hijacking Bitcoin: Routing Attacks on Cryptocurrencies [J].
Apostolaki, Maria ;
Zohar, Aviv ;
Vanbever, Laurent .
2017 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2017, :375-392
[5]   A Survey of Attacks on Ethereum Smart Contracts (SoK) [J].
Atzei, Nicola ;
Bartoletti, Massimo ;
Cimoli, Tiziana .
PRINCIPLES OF SECURITY AND TRUST (POST 2017), 2017, 10204 :164-186
[6]  
Cachin C., 2016, WORKSHOP DISTRIBUTED, V310, P1
[7]   Blockchain for Internet of Things: A Survey [J].
Dai, Hong-Ning ;
Zheng, Zibin ;
Zhang, Yan .
IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (05) :8076-8094
[8]  
Dawson, 2017, SECURITY VULNERABILI
[9]  
Dumas J.-G., P 12 INT MULT COMP I, V2021, P1
[10]   Blockchain Technologies for the Internet of Things: Research Issues and Challenges [J].
Ferrag, Mohamed Amine ;
Derdour, Makhlouf ;
Mukherjee, Mithun ;
Derhab, Abdelouahid ;
Maglaras, Leandros ;
Janicke, Helge .
IEEE INTERNET OF THINGS JOURNAL, 2019, 6 (02) :2188-2204