{"title":"Rearguard: A Novel Blockchain-based Automatic Worm Containment System","authors":"Mohamed A. Seifeldin Elsayed","doi":"10.1109/ITC-Egypt52936.2021.9513932","DOIUrl":null,"url":null,"abstract":"Cyberattacks constitute a significant threat to information technology systems. Computer worms are used to conduct cyberattacks to compromise computers and the data stored on them. The self-propagation characteristic of computer worms allows them to spread fast and infect many hosts in a computer network. Thus, this makes it difficult for humans to deploy a timely countermeasure to confront worm infections within the attacked network. Worm containment is utilized to stop worm spread in a computer network. The containment technique should be automatic, timely, reliable, and implemented in a distributed manner. In this paper, we introduce Rearguard, a novel blockchain-based automatic worm containment system. Rearguard achieves worm containment by creating and distributing vulnerability-based filters for the vulnerabilities being exploited. A vulnerability-based filter is employed to drop any received network message contains variants of a worm that attempts to exploit the same vulnerability. The vulnerability-based filter generation is carried out utilizing a blockchain smart contract deployed in the attacked network. The blockchain ensures reliability, timely response, trustworthy filters, and the availability of all filters in a distributed ledger that is maintained by network hosts. Rearguard has been implemented against a synthetic worm. The obtained results show that Rearguard introduces low overhead as well as ensures timely and automatic response to worm attacks.","PeriodicalId":321025,"journal":{"name":"2021 International Telecommunications Conference (ITC-Egypt)","volume":"71 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-07-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 International Telecommunications Conference (ITC-Egypt)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITC-Egypt52936.2021.9513932","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
Cyberattacks constitute a significant threat to information technology systems. Computer worms are used to conduct cyberattacks to compromise computers and the data stored on them. The self-propagation characteristic of computer worms allows them to spread fast and infect many hosts in a computer network. Thus, this makes it difficult for humans to deploy a timely countermeasure to confront worm infections within the attacked network. Worm containment is utilized to stop worm spread in a computer network. The containment technique should be automatic, timely, reliable, and implemented in a distributed manner. In this paper, we introduce Rearguard, a novel blockchain-based automatic worm containment system. Rearguard achieves worm containment by creating and distributing vulnerability-based filters for the vulnerabilities being exploited. A vulnerability-based filter is employed to drop any received network message contains variants of a worm that attempts to exploit the same vulnerability. The vulnerability-based filter generation is carried out utilizing a blockchain smart contract deployed in the attacked network. The blockchain ensures reliability, timely response, trustworthy filters, and the availability of all filters in a distributed ledger that is maintained by network hosts. Rearguard has been implemented against a synthetic worm. The obtained results show that Rearguard introduces low overhead as well as ensures timely and automatic response to worm attacks.