The CTI (Cyber Threat Intelligence) sharing and exchange is an effective method to improve the responsiveness of the protection party. Blockchain technology enables sharing collaboration consortium to conduct a trusted CTI sharing and exchange without a trusted centralized institution. However, the distributed connectivity of the blockchain-based CTI sharing model proposed before exposes the systems into byzantine attacks, the compromised members of partner organizations will further decrease the accuracy and trust level of CTI by generating false reporting. To address the unbalance issues of performance in speed, scalability and security, this paper proposes a new blockchain-based CTI model, which combines consortium blockchain and distributed reputation management systems to achieve automated analysis and response of tactical threat intelligence. In addition, the novel consensus algorithm of consortium blockchain that is fit for CTI sharing and exchange introduced in this paper. The new consensus algorithm is called 'Proof-of Reputation' (PoR) consensus, which meets the requirements of transaction rate and makes the consensus in a creditable network environment through constructing a reputation model. Finally, the effectiveness and security performance of the proposed model and consensus algorithm is verified by experiments.
翻译:CTI(网络威胁情报)共享和交流是提高保护方反应能力的有效方法; 链链技术使共享合作财团能够在没有可信任的中央机构的情况下进行信任的CTI共享和交流; 然而,在将系统暴露于敌国袭击之前提出的基于链式CTI共享模式的分布式连通性将使这些系统暴露于敌国袭击中,伙伴组织的受损害成员将产生虚假报告,从而进一步降低CTI的准确性和信任度; 为解决速度、可扩缩性和安全性方面业绩不平衡的问题,本文件提出了一个新的基于链式CTI模式,该模式将财团的连锁和分布式的名声管理系统结合起来,以实现对战术威胁情报的自动分析和应对; 此外,本文件还介绍了适合CTI共享和交流的基于链式CTI共享的新共识算法; 新的共识算法称为“POR-proforpatation”(POR)共识,它符合交易率的要求,并通过建立信誉模型在可信用网络环境中取得共识。 最后,通过试验核实拟议的模型和协商一致算法的有效性和安全性。