跳到主要导航 跳到搜索 跳到主要内容

TraceBlock: Cyberattack Traceback System Based on Blockchain

  • Beijing Institute of Technology

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

With the continuous development of cyberattack techniques, attack provenance graph has become an important tool for network defense decision-making. Although existing research has made progress in the logical representation and automatic generation of provenance graphs, the provenance graphs constructed by single organization cannot support collaborative traceability. This paper proposes a blockchain-based cyberattack traceback system called TraceBlock to enable the sharing of graphs across multiple organizations. In TraceBlock system, alert records, which are raw data for contracting, are generated by hosts, securely transmitted by oracle, and filtered by CTI filter. The CTI filter uses a pre-trained model to identify critical threat intelligences (CTIs) and uploads CTIs to the blockchain network. Three smart contracts are deployed on the blockchain network, respectively responsible for CTI verification, provenance graph construction, and subgraph extraction. We conduct simulations using an open-source blockchain platform and the DARPA 1999 dataset. The results demonstrate the feasibility of the proposed system.

源语言英语
主期刊名Advanced Security on Software and Systems - International Conference, ASSS 2025, Proceedings
编辑Weizhi Meng, Qingni Shen, Tao Zhang, Jing Yu
出版商Springer Science and Business Media Deutschland GmbH
17-34
页数18
ISBN(印刷版)9783032215994
DOI
出版状态已出版 - 2026
已对外发布
活动4th International Conference on Advanced Security on Software and Systems, ASSS 2025 - Guilin, 中国
期限: 3 12月 20255 12月 2025

出版系列

姓名Communications in Computer and Information Science
2903 CCIS
ISSN(印刷版)1865-0929
ISSN(电子版)1865-0937

会议

会议4th International Conference on Advanced Security on Software and Systems, ASSS 2025
国家/地区中国
Guilin
时期3/12/255/12/25

指纹

探究 'TraceBlock: Cyberattack Traceback System Based on Blockchain' 的科研主题。它们共同构成独一无二的指纹。

引用此