Skip to main content
Erschienen in: Journal of Computer Virology and Hacking Techniques 2/2021

05.01.2021 | Original Paper

Study on a security intelligence trading platform based on blockchain and IPFS

verfasst von: Hejun Xu, Binkai Jiang

Erschienen in: Journal of Computer Virology and Hacking Techniques | Ausgabe 2/2021

Einloggen

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Security response centre (SRC) is an important solution for enterprises to ensuring their network security. The existing security response centres can be mainly divided into two types, the third-party vulnerability reporting platforms and xSRCs of each enterprise. Normally, hackers find and submit valuable information to a vulnerability reporting platform or xSRC. However, the hackers who submit vulnerabilities probably disagree with the assessment results of vulnerability level by enterprises or the third-party platform experts entrusted by enterprises, which may lead to some dangerous situations that can threat the enterprise’s network security. This paper proposes a security intelligence trading platform based on blockchain and IPFS (Inter Planetary File System), and applies it to a specific example. Due to the decentralization and immutability of blockchain technology and IPFS, it can make the vulnerability level assessment fair and just, which will protect the interests and privacy of both hackers and enterprises. The example proves that the proposed method is simple and feasible, and has theoretical and practical value to the exploration of security information transaction mechanism.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
1.
Zurück zum Zitat You, L., Lin, Z., Yue, L., et al.: Design and implementation of security emergency response center platform. Softw. Eng. 01, 24–27 (2018). (in Chinese) You, L., Lin, Z., Yue, L., et al.: Design and implementation of security emergency response center platform. Softw. Eng. 01, 24–27 (2018). (in Chinese)
3.
Zurück zum Zitat Bai, G.: How does the security emergency response center (SRC) work? China Inf Secur 07, 61–62 (2016). (in Chinese) Bai, G.: How does the security emergency response center (SRC) work? China Inf Secur 07, 61–62 (2016). (in Chinese)
4.
Zurück zum Zitat Anderson, R.: Why information security is hard-an economic perspective. In: Computer Security Applications Conference, 2001. ACSAC 2001. Proceedings 17th Annual. IEEE, pp. 358–365 (2001) Anderson, R.: Why information security is hard-an economic perspective. In: Computer Security Applications Conference, 2001. ACSAC 2001. Proceedings 17th Annual. IEEE, pp. 358–365 (2001)
5.
Zurück zum Zitat Anderson, R., Moore, T.: The economics of information security. Science 314(5799), 610–613 (2006)CrossRef Anderson, R., Moore, T.: The economics of information security. Science 314(5799), 610–613 (2006)CrossRef
7.
Zurück zum Zitat Camp, L.J., Wolfram, C.: Pricing security. In: Economics of Information Security, pp. 17–34 (2004) Camp, L.J., Wolfram, C.: Pricing security. In: Economics of Information Security, pp. 17–34 (2004)
8.
Zurück zum Zitat Ozment, A.: Bug auctions: vulnerability markets reconsidered. In: Third Workshop on the Economics of Information Security (2004) Ozment, A.: Bug auctions: vulnerability markets reconsidered. In: Third Workshop on the Economics of Information Security (2004)
9.
Zurück zum Zitat Bohme, R.: A comparison of market approaches to software vulnerability disclosure. Lect. Notes Comput. Sci. 3995, 298–311 (2006)CrossRef Bohme, R.: A comparison of market approaches to software vulnerability disclosure. Lect. Notes Comput. Sci. 3995, 298–311 (2006)CrossRef
10.
Zurück zum Zitat Zhu, L.: Design and Implementation of Distributed Network Emergency Response Management System CHAIRS. Southeast University, Nanjing (2015). (in Chinese) Zhu, L.: Design and Implementation of Distributed Network Emergency Response Management System CHAIRS. Southeast University, Nanjing (2015). (in Chinese)
11.
Zurück zum Zitat Yuan, C., Zhou, Y., Ji, Y., et al.: Construction of snational cyber security emergency response organization against virus threat. Inf. Netw. Secur. 09, 7–10 (2009). (in Chinese) Yuan, C., Zhou, Y., Ji, Y., et al.: Construction of snational cyber security emergency response organization against virus threat. Inf. Netw. Secur. 09, 7–10 (2009). (in Chinese)
12.
Zurück zum Zitat Huang, C.: Developing China’s cyber security emergency response system. Inf. Netw. Secur. 03, 27–28 (2005). (in Chinese) Huang, C.: Developing China’s cyber security emergency response system. Inf. Netw. Secur. 03, 27–28 (2005). (in Chinese)
14.
Zurück zum Zitat Nakamoto, S.: Bitcoin: a peer-to-peer electronic cash system. Consulted (2009) Nakamoto, S.: Bitcoin: a peer-to-peer electronic cash system. Consulted (2009)
Metadaten
Titel
Study on a security intelligence trading platform based on blockchain and IPFS
verfasst von
Hejun Xu
Binkai Jiang
Publikationsdatum
05.01.2021
Verlag
Springer Paris
Erschienen in
Journal of Computer Virology and Hacking Techniques / Ausgabe 2/2021
Elektronische ISSN: 2263-8733
DOI
https://doi.org/10.1007/s11416-020-00375-7

Weitere Artikel der Ausgabe 2/2021

Journal of Computer Virology and Hacking Techniques 2/2021 Zur Ausgabe