A Method and Platform for Security Advisory Dissemination Leveraging Web3 Technologies

Nicola Cibin, Jannik Lucas Sommer, Magnus Mølgard Lund, Michele Albano

Research output: Contribution to book/anthology/report/conference proceedingArticle in proceedingResearchpeer-review

9 Downloads (Pure)

Abstract

The frequency of software supply chain attacks has reached unprecedented levels, primarily due to the increasing reliance on huge numbers of software and hardware dependencies, and the inherent vulnerabilities they harbor. Currently, vendors providing these software and hardware components share security advisories to centralized databases or post them on proprietary websites, which security engineers have to search manually to find vulnerabilities relevant for their systems. Furthermore, the security advisories often do not follow a standard machine-readable format, which results in the engineers having to manually analyze the documents. In this paper, {\em SENTINEL}, a novel solution for automating dissemination and discovery of security advisories leveraging Web3 technologies, is presented. In particular, the Ethereum blockchain is used by vendors to notify asset owners of novel vulnerabilities in their systems in a reliable and accountable manner. Evaluation tests conducted on the Ethereum Sepolia Testnet confirm that our proposal is a functional and functioning solution for securely disseminating and discovering security advisories utilizing a fully decentralized infrastructure. {\em SENTINEL}'s source code is released as open source software on GitHub.
Original languageEnglish
Title of host publicationProceedings of 6th IEEE International Conference on Blockchain
Place of PublicationHaihuadao, China
PublisherIEEE (Institute of Electrical and Electronics Engineers)
Publication date17 Dec 2023
Article number10411464
ISBN (Print)979-8-3503-1930-9
ISBN (Electronic)979-8-3503-1929-3
DOIs
Publication statusPublished - 17 Dec 2023
Event2023 IEEE International Conference on Blockchain - Dubai, United Arab Emirates
Duration: 17 Dec 202321 Dec 2023
https://icbc2023.ieee-icbc.org/

Conference

Conference2023 IEEE International Conference on Blockchain
Country/TerritoryUnited Arab Emirates
CityDubai
Period17/12/202321/12/2023
Internet address
SeriesIEEE International Conference on Blockchain
ISSN2834-9946

Keywords

  • Blockchain
  • Distributed Storage
  • Security Advisories
  • SBOM
  • CSAF

Fingerprint

Dive into the research topics of 'A Method and Platform for Security Advisory Dissemination Leveraging Web3 Technologies'. Together they form a unique fingerprint.

Cite this