<p>This paper addresses the security challenges faced in the adoption of blockchain technology. It presents a comprehensive framework for assessing security risks in blockchain-based applications. This framework is built on threat modeling techniques and cybersecurity standards. The process starts with gathering cyber threat intelligence, focusing on identifying new and emerging threats in the blockchain landscape. Then, threat modeling is performed to pinpoint and analyze potential vulnerabilities based on the system’s high-level design. The STRIDE model is used to categorize identified attack vectors on the system. After that, these vectors are mapped to the MITRE ATT&amp;CK framework for a deeper understanding of how they might be exploited, and they are rated using the DREAD/CVSS models to measure their severity. Finally, to reduce these risks, the framework proposes countermeasures that are aligned with the NIST SP 800-53 Rev 5 guidelines. The proposed framework is applied to decentralized exchange (DEX) and supply chain use cases, demonstrating its effectiveness in identifying, assessing, and mitigating security challenges unique to these systems. The proposed framework in this work offers a comprehensive, scalable, and practical methodology for blockchain security risk assessment. Its key contribution lies in seamlessly integrating widely adopted cybersecurity standards with the unique architectural elements and threat landscape of blockchain systems. Ultimately, this framework will serve as a valuable resource for security professionals and system architects seeking to develop secure-by-design blockchain systems.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A standard-driven framework for blockchain security risk assessment

  • Maher Boughdiri,
  • Mohamed Hkima,
  • Takoua Abdelatif,
  • Chirine Ghedira Guegan

摘要

This paper addresses the security challenges faced in the adoption of blockchain technology. It presents a comprehensive framework for assessing security risks in blockchain-based applications. This framework is built on threat modeling techniques and cybersecurity standards. The process starts with gathering cyber threat intelligence, focusing on identifying new and emerging threats in the blockchain landscape. Then, threat modeling is performed to pinpoint and analyze potential vulnerabilities based on the system’s high-level design. The STRIDE model is used to categorize identified attack vectors on the system. After that, these vectors are mapped to the MITRE ATT&CK framework for a deeper understanding of how they might be exploited, and they are rated using the DREAD/CVSS models to measure their severity. Finally, to reduce these risks, the framework proposes countermeasures that are aligned with the NIST SP 800-53 Rev 5 guidelines. The proposed framework is applied to decentralized exchange (DEX) and supply chain use cases, demonstrating its effectiveness in identifying, assessing, and mitigating security challenges unique to these systems. The proposed framework in this work offers a comprehensive, scalable, and practical methodology for blockchain security risk assessment. Its key contribution lies in seamlessly integrating widely adopted cybersecurity standards with the unique architectural elements and threat landscape of blockchain systems. Ultimately, this framework will serve as a valuable resource for security professionals and system architects seeking to develop secure-by-design blockchain systems.