A Secure and Reliable Blockchain-based Audit Log System

Zhonghao Liu, Xinwei Zhang, Guyue Li, Helei Cui, Jiaheng Wang, Bin Xiao

科研成果: 书/报告/会议事项章节会议稿件同行评审

2 引用 (Scopus)

摘要

The use of log files in digital forensics highlights the importance of ensuring their data integrity for auditing purposes. However, traditional centralized audit log systems face challenges in maintaining data integrity due to log injection attacks and single-point failures. Although blockchain technology can accurately process and replicate log files, existing blockchain-based audit log systems still suffer from security and reliability issues due to their weak threat models and limited scalability. To address these concerns, we propose a blockchain-based audit log system that ensures data integrity under a general threat model where a part of the nodes, including loggers and auditors, are untrusted. First, our proposed system resists collusion attacks by incorporating multiple nodes for system processes and utilizing smart contracts to enforce consensus algorithms. Second, to save blockchain storage space, we design an efficient log integrity proof method, which generates a sub-Non-Fungible Token (sub-NFT) for each log file and keeps it on the blockchain as integrity proof. The single-point failure problem is resolved by outsourcing log files to a distributed file system. To evaluate the proposed system, we implement a prototype based on Hyperledger Fabric. Experimental results show that our proof generation method can reduce storage space usage in comparison to other blockchain-based audit log systems, saving approximately 50% of space in Hyperledger Fabric. The security analysis proves that our system can ensure log file data integrity under the proposed threat model.

源语言英语
主期刊名ICC 2024 - IEEE International Conference on Communications
编辑Matthew Valenti, David Reed, Melissa Torres
出版商Institute of Electrical and Electronics Engineers Inc.
2010-2015
页数6
ISBN(电子版)9781728190549
DOI
出版状态已出版 - 2024
活动59th Annual IEEE International Conference on Communications, ICC 2024 - Denver, 美国
期限: 9 6月 202413 6月 2024

出版系列

姓名IEEE International Conference on Communications
ISSN(印刷版)1550-3607

会议

会议59th Annual IEEE International Conference on Communications, ICC 2024
国家/地区美国
Denver
时期9/06/2413/06/24

指纹

探究 'A Secure and Reliable Blockchain-based Audit Log System' 的科研主题。它们共同构成独一无二的指纹。

引用此