Blockchain-Based Architecture for Secured Cyber-Attack Features Exchange

Blockchain-Based Architecture for Secured Cyber-Attack Features Exchange
复制标题

DOI:
10.1109/cscloud-edgecom49738.2020.00025
复制
发表时间:
2020-08
期刊:
2020 7th IEEE International Conference on Cyber Security and Cloud Computing (CSCloud)/2020 6th IEEE International Conference on Edge Computing and Scalable Cloud (EdgeCom)
影响因子:
--
通讯作者:
O. Ajayi;T. Saadawi
O. Ajayi;T. Saadawi
中科院分区:
其他
文献类型:
--
作者:
O. Ajayi;T. Saadawi

文献摘要

相似文献

尽管入侵检测系统 (IDS) 在识别计算机网络和连接到互联网的设备中的网络攻击方面的准确性有所提高,但分布式或协同攻击仍然可能未被检测到或未及时检测到。单一的有利位置限制了这些 IDS 检测此类攻击的能力。因此,不同IDS节点之间需要交换攻击特征。研究人员提出了一种协作入侵检测系统来有效共享这些攻击特征。这种方法很有用;但共享数据的安全性无法得到保证。更具体地说,维护共享数据的完整性和一致性成为一个重要问题。在本文中,我们提出了一种基于区块链的解决方案,确保协作入侵检测系统中共享的攻击特征的完整性和一致性。所提出的架构通过检测和防止虚假特征注入和受损的 IDS 节点来实现这一目标。它还促进了 IDS 节点之间可扩展的攻击特征交换,确保异构 IDS 节点参与,并且对于加入和离开网络的公共 IDS 节点具有鲁棒性。我们评估安全分析和延迟。结果表明,所提出的方法可以检测并防止受损的 IDS 节点、恶意特征注入、操纵或删除,并且具有低延迟的可扩展性。
Despite the increased accuracy of intrusion detection systems (IDS) in identifying cyberattacks in computer networks and devices connected to the internet, distributed or coordinated attacks can still go undetected or not detected on time. The single vantage point limits the ability of these IDSs to detect such attacks. Due to this reason, there is a need for attack characteristics’ exchange among different IDS nodes. Researchers proposed a cooperative intrusion detection system to share these attack characteristics effectively. This approach was useful; however, the security of the shared data cannot be guaranteed. More specifically, maintaining the integrity and consistency of shared data becomes a significant concern. In this paper, we propose a blockchain-based solution that ensures the integrity and consistency of attack characteristics shared in a cooperative intrusion detection system. The proposed architecture achieves this by detecting and preventing fake features injection and compromised IDS nodes. It also facilitates scalable attack features exchange among IDS nodes, ensures heterogeneous IDS nodes participation, and it is robust to public IDS nodes joining and leaving the network. We evaluate the security analysis and latency. The result shows that the proposed approach detects and prevents compromised IDS nodes, malicious features injection, manipulation, or deletion, and it is also scalable with low latency.