首页> 外文期刊>Digital investigation >Frameup: An incriminatory attack on Storj: A peer to peer blockchain enabled distributed storage system
【24h】

Frameup: An incriminatory attack on Storj: A peer to peer blockchain enabled distributed storage system

机译:框架:对STORJ的罪恶攻击:对等区块链的对等体的分布式存储系统

获取原文
获取原文并翻译 | 示例
           

摘要

In this work we present a primary account of frameup, an incriminatory attack made possible because of existing implementations in distributed peer to peer storage. The frameup attack shows that an adversary has the ability to store unencrypted data on the hard drives of people renting out their hard drive space. This is important to forensic examiners as it opens the door for possibly framing an innocent victim. Our work employs Storj as an example technology, due to its popularity and market size. Storj is a blockchain enabled system that allows people to rent out their hard drive space to other users around the world by employing a cryptocurrency token that is used to pay for the services rendered. It uses blockchain features like a transaction ledger, public/private key encryption, and cryptographic hash functions - but this work is not centered around blockchain. Our work discusses two frameup attacks, a preliminary and an optimized attack, both of which take advantage of Storj's implementation. Results illustrate that Storj allows a potential adversary to store incriminating unencrypted files, or parts of files that are viewable on people's systems when renting out their unused hard drive space. We offer potential solutions to mitigate our discovered attacks, a developed tool to review if a person has been a victim of a frameup attack, and a mechanism for showing that the files were stored on a hard drive without the renter's knowledge. Our hope is that this work will inspire future security and forensics research directions in the exploration of distributed peer to peer storage systems that embrace blockchain and cryptocurrency tokens. (C) 2019 Elsevier Ltd. All rights reserved.
机译:在这项工作中,我们介绍了帧的主要陈述,因为分布式对等存储器中的现有实现,所以取消敏感性攻击。帧攻击表明,对手有能力将未加密的数据存储在租用其硬盘空间的人们的硬盘上。这对法医审查员来说是重要的,因为它打开了可能框架无辜的受害者的门。由于其受欢迎程度和市场规模,我们的工作雇用了Storj作为示例技术。 Storj是一个支持的SloctChain系统,允许人们通过使用用于支付所呈现的服务的加密货币令牌来将其硬盘空间租用到世界各地的其他用户。它使用BlockChain特征,如事务分类帐,公共/私钥加密和加密散列函数,但这项工作不在区块链周围居中。我们的工作讨论了两个帧攻击,初步和优化的攻击,这两者都利用Storj的实现。结果说明Storj允许潜在的对手存储归人的未加密文件,或在租用未使用的硬盘空间时可在人们系统上查看的部分文件。我们提供潜在的解决方案来缓解我们发现的攻击,是一个审查一个人的发达的工具,如果一个人是帧攻击的受害者,以及显示文件在没有租盘的知识的情况下存储文件的机制。我们希望这项工作将激发未来的安全和取证研究方向,以探索分布式对等储存系统,该储存系统拥抱区块链和加密货币。 (c)2019 Elsevier Ltd.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号