A Method and Platform for Security Advisory Dissemination Leveraging Web3 Technologies

Nicola Cibin, Jannik Lucas Sommer, Magnus Mølgard Lund, Michele Albano

Publikation: Bidrag til bog/antologi/rapport/konference proceedingKonferenceartikel i proceedingForskningpeer review

Abstract

The frequency of software supply chain attacks has reached unprecedented levels, primarily due to the increasing reliance on huge numbers of software and hardware dependencies, and the inherent vulnerabilities they harbor. Currently, vendors providing these software and hardware components share security advisories to centralized databases or post them on proprietary websites, which security engineers have to search manually to find vulnerabilities relevant for their systems. Furthermore, the security advisories often do not follow a standard machine-readable format, which results in the engineers having to manually analyze the documents. In this paper, {\em SENTINEL}, a novel solution for automating dissemination and discovery of security advisories leveraging Web3 technologies, is presented. In particular, the Ethereum blockchain is used by vendors to notify asset owners of novel vulnerabilities in their systems in a reliable and accountable manner. Evaluation tests conducted on the Ethereum Sepolia Testnet confirm that our proposal is a functional and functioning solution for securely disseminating and discovering security advisories utilizing a fully decentralized infrastructure. {\em SENTINEL}'s source code is released as open source software on GitHub.
OriginalsprogEngelsk
TitelProceedings of 6th IEEE International Conference on Blockchain
UdgivelsesstedHaihuadao, China
ForlagIEEE (Institute of Electrical and Electronics Engineers)
Publikationsdato17 dec. 2023
Artikelnummer10411464
ISBN (Trykt)979-8-3503-1930-9
ISBN (Elektronisk)979-8-3503-1929-3
DOI
StatusUdgivet - 17 dec. 2023
Begivenhed2023 IEEE International Conference on Blockchain - Dubai, United Arab Emirates
Varighed: 17 dec. 202321 dec. 2023
https://icbc2023.ieee-icbc.org/

Konference

Konference2023 IEEE International Conference on Blockchain
Land/OmrådeUnited Arab Emirates
ByDubai
Periode17/12/202321/12/2023
Internetadresse
NavnIEEE International Conference on Blockchain
ISSN2834-9946

Fingeraftryk

Dyk ned i forskningsemnerne om 'A Method and Platform for Security Advisory Dissemination Leveraging Web3 Technologies'. Sammen danner de et unikt fingeraftryk.

Citationsformater