Rearguard: A Novel Blockchain-based Automatic Worm Containment System

Mohamed A. Seifeldin Elsayed
{"title":"Rearguard: A Novel Blockchain-based Automatic Worm Containment System","authors":"Mohamed A. Seifeldin Elsayed","doi":"10.1109/ITC-Egypt52936.2021.9513932","DOIUrl":null,"url":null,"abstract":"Cyberattacks constitute a significant threat to information technology systems. Computer worms are used to conduct cyberattacks to compromise computers and the data stored on them. The self-propagation characteristic of computer worms allows them to spread fast and infect many hosts in a computer network. Thus, this makes it difficult for humans to deploy a timely countermeasure to confront worm infections within the attacked network. Worm containment is utilized to stop worm spread in a computer network. The containment technique should be automatic, timely, reliable, and implemented in a distributed manner. In this paper, we introduce Rearguard, a novel blockchain-based automatic worm containment system. Rearguard achieves worm containment by creating and distributing vulnerability-based filters for the vulnerabilities being exploited. A vulnerability-based filter is employed to drop any received network message contains variants of a worm that attempts to exploit the same vulnerability. The vulnerability-based filter generation is carried out utilizing a blockchain smart contract deployed in the attacked network. The blockchain ensures reliability, timely response, trustworthy filters, and the availability of all filters in a distributed ledger that is maintained by network hosts. Rearguard has been implemented against a synthetic worm. The obtained results show that Rearguard introduces low overhead as well as ensures timely and automatic response to worm attacks.","PeriodicalId":321025,"journal":{"name":"2021 International Telecommunications Conference (ITC-Egypt)","volume":"71 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2021-07-13","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2021 International Telecommunications Conference (ITC-Egypt)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ITC-Egypt52936.2021.9513932","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

Cyberattacks constitute a significant threat to information technology systems. Computer worms are used to conduct cyberattacks to compromise computers and the data stored on them. The self-propagation characteristic of computer worms allows them to spread fast and infect many hosts in a computer network. Thus, this makes it difficult for humans to deploy a timely countermeasure to confront worm infections within the attacked network. Worm containment is utilized to stop worm spread in a computer network. The containment technique should be automatic, timely, reliable, and implemented in a distributed manner. In this paper, we introduce Rearguard, a novel blockchain-based automatic worm containment system. Rearguard achieves worm containment by creating and distributing vulnerability-based filters for the vulnerabilities being exploited. A vulnerability-based filter is employed to drop any received network message contains variants of a worm that attempts to exploit the same vulnerability. The vulnerability-based filter generation is carried out utilizing a blockchain smart contract deployed in the attacked network. The blockchain ensures reliability, timely response, trustworthy filters, and the availability of all filters in a distributed ledger that is maintained by network hosts. Rearguard has been implemented against a synthetic worm. The obtained results show that Rearguard introduces low overhead as well as ensures timely and automatic response to worm attacks.
后卫:一种新的基于区块链的自动蠕虫遏制系统
网络攻击对信息技术系统构成重大威胁。计算机蠕虫被用来进行网络攻击,以破坏计算机和存储在其中的数据。计算机蠕虫的自传播特性使它们能够快速传播并感染计算机网络中的许多主机。因此,这使得人们很难部署及时的对策来对抗受攻击网络中的蠕虫感染。蠕虫遏制是用来阻止蠕虫在计算机网络中的传播。围堵技术应该是自动的、及时的、可靠的,并以分布式的方式实施。在本文中,我们介绍了一种新的基于区块链的自动蠕虫遏制系统后卫。guard通过为被利用的漏洞创建和分发基于漏洞的过滤器来实现蠕虫遏制。基于漏洞的过滤器用于丢弃任何接收到的包含试图利用相同漏洞的蠕虫变体的网络消息。基于漏洞的过滤器生成是利用部署在受攻击网络中的区块链智能合约进行的。区块链确保了网络主机维护的分布式账本中的可靠性、及时响应、可信过滤器以及所有过滤器的可用性。后卫已经实现了对抗合成蠕虫。实验结果表明,该算法降低了系统开销,保证了对蠕虫攻击的及时、自动响应。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信