This paper considers the use of novel technologies for mitigating attacks that aim at compromising intrusion detection systems (IDSs). Solutions based on collaborative intrusion detection networks (CIDNs) could increase the resilience against such attacks as they allow IDS nodes to gain knowledge from each other by sharing information. However, despite the vast research in this area, trust management issues still pose significant challenges and recent works investigate whether these could be addressed by relying on blockchain and related distributed ledger technologies. Towards that direction, the paper proposes the use of a trust-based blockchain in CIDNs, referred to as trust-chain, to protect the integrity of the information shared among the CIDN peers, enhance their accountability, and secure their collaboration by thwarting insider attacks. A consensus protocol is proposed for CIDNs, which is a combination of a proof-of-stake and proof-of-work protocols, to enable collaborative IDS nodes to maintain a reliable and tampered-resistant trust-chain.
翻译:本文探讨了如何利用新技术来减轻旨在损害入侵探测系统的攻击。基于合作入侵探测网络的解决办法可以提高抵御这类攻击的复原力,因为这些办法可以使国际争端解决网络的节点通过分享信息而相互获取知识。然而,尽管在这一领域进行了广泛的研究,但信任管理问题仍构成重大挑战,最近还开展了一些工作,以调查是否可以通过依赖块链和相关分布式分类账技术来解决这些问题。为此,本文件提议使用CIDN网络中以信任为基础的块链,称为信任链,以保护CIDN同侪之间共享的信息的完整性,加强其问责制,并通过挫败内幕攻击确保彼此合作。为CIDS网络提出了一个共识协议,这是对获取证据和工作证明的结合,目的是使IDS合作的节点能够维持可靠和受破坏的信任链。