Skip to main navigation Skip to search Skip to main content

TraceBlock: Cyberattack Traceback System Based on Blockchain

  • Beijing Institute of Technology

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

With the continuous development of cyberattack techniques, attack provenance graph has become an important tool for network defense decision-making. Although existing research has made progress in the logical representation and automatic generation of provenance graphs, the provenance graphs constructed by single organization cannot support collaborative traceability. This paper proposes a blockchain-based cyberattack traceback system called TraceBlock to enable the sharing of graphs across multiple organizations. In TraceBlock system, alert records, which are raw data for contracting, are generated by hosts, securely transmitted by oracle, and filtered by CTI filter. The CTI filter uses a pre-trained model to identify critical threat intelligences (CTIs) and uploads CTIs to the blockchain network. Three smart contracts are deployed on the blockchain network, respectively responsible for CTI verification, provenance graph construction, and subgraph extraction. We conduct simulations using an open-source blockchain platform and the DARPA 1999 dataset. The results demonstrate the feasibility of the proposed system.

Original languageEnglish
Title of host publicationAdvanced Security on Software and Systems - International Conference, ASSS 2025, Proceedings
EditorsWeizhi Meng, Qingni Shen, Tao Zhang, Jing Yu
PublisherSpringer Science and Business Media Deutschland GmbH
Pages17-34
Number of pages18
ISBN (Print)9783032215994
DOIs
Publication statusPublished - 2026
Externally publishedYes
Event4th International Conference on Advanced Security on Software and Systems, ASSS 2025 - Guilin, China
Duration: 3 Dec 20255 Dec 2025

Publication series

NameCommunications in Computer and Information Science
Volume2903 CCIS
ISSN (Print)1865-0929
ISSN (Electronic)1865-0937

Conference

Conference4th International Conference on Advanced Security on Software and Systems, ASSS 2025
Country/TerritoryChina
CityGuilin
Period3/12/255/12/25

Keywords

  • Blockchain
  • Provenance graph
  • Smart Contract
  • Subgraph extraction

Fingerprint

Dive into the research topics of 'TraceBlock: Cyberattack Traceback System Based on Blockchain'. Together they form a unique fingerprint.

Cite this