首页> 外文期刊>Future generation computer systems >Designing collaborative blockchained signature-based intrusion detection in IoT environments
【24h】

Designing collaborative blockchained signature-based intrusion detection in IoT environments

机译:在IOT环境中设计基于组合的基于签名的入侵检测

获取原文
获取原文并翻译 | 示例
           

摘要

With the rapid development of Internet-of-Things (IoT), there is an increasing demand for securing the IoT environments. For such purpose, intrusion detection systems (IDSs) are one of the most important security mechanisms, which can help defend computer networks including IoT against various threats. In order to achieve better detection performance, collaborative intrusion detection systems or networks (CIDSs or CIDNs) are often adopted in a practical scenario, allowing a set of IDS nodes to exchange required information with each other, e.g., alarms, signatures. However, due to the distributed nature, such kind of collaborative network is vulnerable to insider attacks, i.e., malicious nodes can generate untruthful signatures and share to normal peers. This may cause intruders to be undetected and greatly degrade the effectiveness of IDSs. With the advent of blockchain technology, it provides a way to verify shared signatures (rules). In this work, our motivation is to develop CBSigIDS, a generic framework of collaborative blockchained signature-based IDSs, which can incrementally build and update a trusted signature database in a collaborative IoT environment. CBSigIDS can provide a verifiable manner in distributed architectures without the need of a trusted intermediary. In the evaluation, our results demonstrate that CBSigIDS can enhance the robustness and effectiveness of signature-based IDSs under adversarial scenarios. (C) 2019 Elsevier B.V. All rights reserved.
机译:随着互联网的快速发展(物联网),对确保物联网环境的需求越来越大。出于这种目的,入侵检测系统(IDS)是最重要的安全机制之一,可以帮助防御包括IOT的计算机网络,以反对各种威胁。为了实现更好的检测性能,通常在实际场景中采用协作入侵检测系统或网络(CIDS或CIDNS或CIDNS),允许一组IDS节点彼此交换所需信息,例如警报,签名。然而,由于分布式性质,这种协作网络容易受到内幕攻击的攻击,即恶意节点可以生成不真实的签名并分享到正常对等体。这可能导致入侵者未被发现并大大降低IDS的有效性。随着BloctChain技术的出现,它提供了一种验证共享签名(规则)的方法。在这项工作中,我们的动机是开发CBSIGID,这是一种基于协作块的签名的IDS的通用框架,可以逐步构建和更新协作IOT环境中的可信签名数据库。 CBSigID可以在分布式架构中提供可验证的方式,而无需受信任的中间人。在评估中,我们的结果表明,CBSIGID可以在对抗方案下提高基于签名的IDS的鲁棒性和有效性。 (c)2019 Elsevier B.v.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号